Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cache poisoning and web application firewall bypass enabling XSS attacks
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an HTTP request smuggling flaw caused by improper parsing of the HTTP transfer‑encoding request header. By sending a specially crafted header, an attacker can poison the web cache, bypass the web application firewall, and execute cross‑site scripting attacks. This flaw falls under CWE‑444 and can compromise the integrity of cached content and the confidentiality of user data, while also allowing denial of service if the cache is overloaded.

Affected Systems

Affected systems include IBM WebSphere Application Server 9.0 prior to version 9.0.5.29 and IBM WebSphere Application Server 8.5 prior to version 8.5.5.31, both the traditional and Liberty editions. The CWE‑444‑identified improper header handling applies to these deployments.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of <1% suggests a low probability of exploitation, so the current exploitation likelihood is still unclear. The likely attack vector is via the public network using HTTP, requiring an attacker to send a crafted transfer‑encoding header to the target server to trigger the smuggling and achieve cache poisoning or WAF bypass.

Generated by OpenCVE AI on September 20, 2026 at 22:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply Fix Pack 9.0.5.29 SB0030823 or later for WebSphere Application Server 9.0.
  • Apply Fix Pack 8.5.5.31 or later for WebSphere Application Server 8.5.
  • Configure the front‑end web server or WAF to reject or strictly validate HTTP transfer‑encoding headers as a temporary mitigation until the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-444
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T14:37:29.521Z

Reserved: 2026-07-10T13:16:32.862Z

Link: CVE-2026-15396

cve-icon Vulnrichment

Updated: 2026-09-15T14:37:25.886Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:38.153

Modified: 2026-09-16T19:22:22.797

Link: CVE-2026-15396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')