Impact
The vulnerability is a path‑segment injection in the collective routing mechanism of IBM WebSphere Application Server Liberty, which can allow an attacker to modify routing paths and potentially execute arbitrary code on the server.
Affected Systems
The affected products are IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 when the collectiveController‑1.0 feature is enabled. The official advisory covers all releases in this range and recommends applying fixes for APAR DT496531 or upgrading to Liberty Fix Pack 26.0.0.9 or later.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity issue. The EPSS score is less than 1 %, suggesting a very low current exploitation probability. It is not listed in the CISA KEV catalog. Exploitation would likely involve sending specially crafted path segments to the collective controller over the network. Therefore the risk remains moderate, but deploying the recommended fixes is strongly advised to eliminate the possibility of remote code execution.
OpenCVE Enrichment