Impact
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain a cross‑site request forgery flaw when the collectiveController-1.0 feature is enabled. This weakness, identified as improper privilege management (CWE-269), allows an attacker to trick the server into making requests to arbitrary internal or external resources, effectively executing server‑side requests with elevated privileges. The consequence is the potential for data exfiltration, internal network compromise, or further lateral movement within the organization.
Affected Systems
The affected product is IBM WebSphere Application Server Liberty in the version range 17.0.0.3 to 26.0.0.8. The vulnerability is present only when the collectiveController-1.0 feature is enabled; systems without this feature are not impacted.
Risk and Exploitability
The CVSS score of 8.3 classifies this vulnerability as High. The EPSS score is < 1%, and it is not listed in the CISA KEV catalog. Exploitation requires remote access to the application and the presence of the collectiveController-1.0 feature. If an attacker can submit crafted requests, they may trigger SSRF attacks that run with the server’s privileges.
OpenCVE Enrichment