Impact
The vulnerability allows remote code execution through a path‑segment injection in the collectiveController‑1.0 feature of IBM WebSphere Application Server Liberty. It can be triggered by an unauthenticated attacker, providing the ability to execute arbitrary code and compromise the confidentiality, integrity and availability of the system. The weakness is classified as CWE‑306, an authentication failure that permits execution of commands without proper authorization.
Affected Systems
Affected are IBM WebSphere Application Server Liberty releases 17.0.0.3 through 26.0.0.8 when the collectiveController‑1.0 feature is enabled. If the feature is disabled in the configuration, the vulnerability does not apply. The product covers all platforms supported by IBM WebSphere Application Server Liberty.
Risk and Exploitability
The CVSS score of 7.1 signals a moderate to high severity level, however the EPSS score of less than 1% indicates the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote access to the collectiveController endpoint, implying a network‑based attack vector.
OpenCVE Enrichment