Impact
IBM WebSphere Application Server versions prior to 9.0.5.29 and 8.5.5.31 contain a log injection flaw that can be triggered through crafted LTPA token cookies. An attacker able to send an HTTP request with the malicious cookie can inject arbitrary text into the server logs. This does not provide execution or disclosure of secrets, but it can conceal the attacker’s actions, facilitate cover‑up, and make forensic analysis more difficult. The weakness is a classic case of improper input validation during log processing, as identified by CWE‑117.
Affected Systems
The affected platforms are IBM WebSphere Application Server 9.0 (all releases 9.0.0.0 through 9.0.5.28) and 8.5 (all releases 8.5.0.0 through 8.5.5.30). Only in the later fix packs (9.0.5.29 and 8.5.5.31) will the vulnerability be resolved.
Risk and Exploitability
The CVSS score of 3.7 indicates low base severity, and no EPSS data is available; the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, as it relies on a crafted cookie sent to the application over HTTP or HTTPS. There are no known public exploits as of the last advisory, but an attacker who can persuade a client to send the cookie could trigger the injection. Given the low severity and lack of active exploitation data, the likelihood of misuse is considered low, yet remediation is still recommended to maintain log integrity.
OpenCVE Enrichment