Impact
IBM CICS Transaction Gateway for Multiplatforms versions 9.1.0.0, 9.2.0.0, 9.3.0.0, and 10.1.0.0, as well as IBM WebSphere Application Server 8.5, 9.0 and Liberty 17.0.0.3 through 26.0.0.6, contain an HTTP request smuggling flaw that can let attackers manipulate HTTP request parsing, potentially leading to tampering of request data and compromising application integrity. This weakness corresponds to CWE‑444 and may allow an attacker to alter or discard parts of a request or response.
Affected Systems
The affected servers include IBM CICS Transaction Gateway for Multiplatforms 9.1.0.0, 9.2.0.0, 9.3.0.0, and 10.1.0.0, as well as IBM WebSphere Application Server 8.5 and 9.0, and IBM WebSphere Application Server – Liberty 17.0.0.3 through 26.0.0.6.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, with an EPSS score of less than 1% and no KEV listing. Based on the description, the likely remote attack vector is an attacker sending crafted HTTP traffic to a vulnerable CICS Transaction Gateway for Multiplatforms or WebSphere Application Server instance. Successful exploitation could allow tampering of request handling, leading to unauthorized data access or service disruption.
OpenCVE Enrichment