Impact
IBM WebSphere Application Server and WebSphere Liberty, which are part of IBM CICS TX Advanced, contain an HTTP request smuggling vulnerability identified as CWE‑444. The flaw lets attackers craft HTTP requests that are interpreted differently by the server, potentially enabling request injection, bypassing authentication checks, or exposing sensitive data.
Affected Systems
The affected product is IBM CICS TX Advanced version 10.1 for Linux, which ships with WebSphere Liberty and is vulnerable to the described request smuggling flaw.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate potential impact, while the EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating a lower likelihood of exploitation in the wild. Attackers would need network access to send crafted HTTP traffic to the exposed endpoints; no local privilege escalation is required, and the attack surface is limited to the HTTP interface.
OpenCVE Enrichment