Description
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Request Smuggling
Action: Patch Now
AI Analysis

Impact

The vulnerability allows HTTP request smuggling because IBM WebSphere Application Server 8.5 improperly processes Content‑Length headers. An attacker can send a crafted request that contains multiple logical requests in a single packet, causing the server and any upstream components to misinterpret the request boundaries. This misinterpretation can lead to message tampering, bypassing of security controls, or denial of service.

Affected Systems

IBM WebSphere Application Server 8.5, versions 8.5.0.0 through 8.5.5.30, is impacted. The fix is contained in fix pack 8.5.5.31 or any later release and is identified by APAR PH71679.

Risk and Exploitability

The CVSS score is 6.5 indicating a moderate risk. No EPSS score is published, which suggests a lower probability of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access to the server and could exploit the flaw remotely, but no privilege escalation is required. The attack vector is likely remote over HTTP, making it potentially exploitable by anyone with connectivity to the application.

Generated by OpenCVE AI on September 19, 2026 at 10:49 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71679. For IBM WebSphere Application Server traditional: For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack  8.5.5.31 https://www.ibm.com/support/pages/node/7285869  (availability September 2026) or later fix pack.  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Apply IBM WebSphere Application Server fix pack 8.5.5.31 or a later release containing APAR PH71679.
  • If an interim fix is pending, configure network edge devices or a web application firewall to enforce strict Content‑Length validation and block malformed requests until the patch is applied.
  • Conduct regression testing to confirm that request smuggling no longer occurs and verify that all inbound traffic is correctly parsed.

Generated by OpenCVE AI on September 19, 2026 at 10:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
Title IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-444
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:42.506Z

Reserved: 2026-06-08T23:57:43.337Z

Link: CVE-2026-11710

cve-icon Vulnrichment

Updated: 2026-09-19T14:09:12.393Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:01.097

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-11710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')