Impact
The vulnerability allows HTTP request smuggling because IBM WebSphere Application Server 8.5 improperly processes Content‑Length headers. An attacker can send a crafted request that contains multiple logical requests in a single packet, causing the server and any upstream components to misinterpret the request boundaries. This misinterpretation can lead to message tampering, bypassing of security controls, or denial of service.
Affected Systems
IBM WebSphere Application Server 8.5, versions 8.5.0.0 through 8.5.5.30, is impacted. The fix is contained in fix pack 8.5.5.31 or any later release and is identified by APAR PH71679.
Risk and Exploitability
The CVSS score is 6.5 indicating a moderate risk. No EPSS score is published, which suggests a lower probability of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access to the server and could exploit the flaw remotely, but no privilege escalation is required. The attack vector is likely remote over HTTP, making it potentially exploitable by anyone with connectivity to the application.
OpenCVE Enrichment