Impact
The vulnerability arises from improper parsing of the HTTP transfer‑encoding header, allowing HTTP request smuggling. With a crafted request, WebSphere may treat multiple requests as one, leading to web cache poisoning, bypass of a Web Application Firewall, and enabling cross‑site scripting attacks. This weakness is categorized as CWE‑444.
Affected Systems
IBM WebSphere Application Server versions prior to 9.0.5.29 in the 9.0.x line and prior to 8.5.5.31 in the 8.5.x line are affected; the Liberty profile is also mentioned as vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate risk. An EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the issue is not listed in CISA KEV. The likely attack vector is network‑based request smuggling. Based on the description, an attacker sending a specially crafted HTTP transfer‑encoding header could cause WebSphere to treat multiple requests as one, leading to cache poisoning, WAF bypass, and XSS. Successful exploitation can result in compromise of user sessions or sensitive data.
OpenCVE Enrichment