Impact
IBM WebSphere Application Server Liberty, shipped with IBM CICS TX Advanced, contains an HTTP request smuggling vulnerability. Crafted HTTP requests can bypass the server's normal request parsing logic, allowing an attacker to insert or forge additional request data. This manipulation can lead to unauthorized data visibility, alteration of application behavior, or service disruption, and may serve as a foothold for more serious exploitation depending on the application context.
Affected Systems
The affected product is IBM CICS TX Advanced, version 10.1 on Linux. The vulnerability is present in the WebSphere Application Server Liberty component bundled with this product.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, implying no widely known exploitation at present. The likely attack vector is over the network via HTTP traffic to the affected Liberty application server, requiring an external actor to send specially crafted requests.
OpenCVE Enrichment