Impact
IBM WebSphere Application Server and its Liberty profile, when bundled with IBM CICS TX Advanced, have a virtual host bypass flaw. The vulnerability arises from improper access control (CWE‑284), allowing an attacker to manipulate virtual host settings and access application resources that should be protected. Attackers could read or alter data, invoke services, or execute privileged actions within the application server scope. Confidentiality, integrity, and potentially availability of the protected services are at risk if exploited.
Affected Systems
IBM CICS TX Advanced version 10.1 running on Linux is affected. The issue manifests within the Liberty runtime incorporated in this product, impacting any virtual hosts configured on the server.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score is not available, so the precise exploitation likelihood is uncertain. The vulnerability is listed as not being in CISA KEV. The likely attack vector is remote, via crafted HTTP requests that target the virtual host configuration of the WebSphere Liberty component. Even though exploitation conditions are not exhaustively described, the vulnerability could be leveraged by attackers with network access to the application server to bypass access controls and gain unauthorized privileges.
OpenCVE Enrichment