Description
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Published: 2026-09-18
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: HTTP request smuggling that may allow request injection, authentication bypass, or data exposure
Action: Apply Patch
AI Analysis

Impact

IBM WebSphere Application Server and WebSphere Liberty, which are part of IBM CICS TX Advanced, contain an HTTP request smuggling vulnerability identified as CWE‑444. The flaw lets attackers craft HTTP requests that are interpreted differently by the server, potentially enabling request injection, bypassing authentication checks, or exposing sensitive data.

Affected Systems

The affected product is IBM CICS TX Advanced version 10.1 for Linux, which ships with WebSphere Liberty and is vulnerable to the described request smuggling flaw.

Risk and Exploitability

The CVSS score of 4.8 reflects moderate potential impact, while the EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating a lower likelihood of exploitation in the wild. Attackers would need network access to send crafted HTTP traffic to the exposed endpoints; no local privilege escalation is required, and the attack surface is limited to the HTTP interface.

Generated by OpenCVE AI on September 19, 2026 at 10:50 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by downloading and applying the below fix. ProductVersionPlatformRemediation/FixIBM CICS TX Advanced10.1Linux Download and apply the update from  Fix Central https://www.ibm.com/support/fixcentral/quickorder


OpenCVE Recommended Actions

  • Download and install the IBM CICS TX Advanced 10.1 update from Fix Central.
  • Restart the WebSphere Liberty services to activate the applied fix.
  • Monitor network traffic and application logs for suspicious HTTP request patterns after the update.

Generated by OpenCVE AI on September 19, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
Title Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.
First Time appeared Ibm
Ibm cics Tx Advanced
Weaknesses CWE-444
CPEs cpe:2.3:a:ibm:cics_tx_advanced:10.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cics_tx_advanced:10.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cics Tx Advanced
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Cics Tx Advanced
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:42.648Z

Reserved: 2026-06-08T03:23:44.255Z

Link: CVE-2026-11548

cve-icon Vulnrichment

Updated: 2026-09-19T14:09:24.508Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:00.783

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-11548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')