Impact
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8 contain a flaw that permits an attacker to cause the server to become unavailable when the restConnector‑2.0 feature is active, resulting in a denial of service attack that impacts the availability of hosted applications. The weakness is identified as CWE-674, a failure to properly check for exceptional conditions.
Affected Systems
Systems running IBM WebSphere Application Server Liberty from version 17.0.0.3 up to 26.0.0.8 that have the restConnector‑1.0 or restConnector‑2.0 feature enabled are affected. The vulnerability is specific to installations where those features are active.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact on availability, while the EPSS score of less than 1% suggests that exploitation in the wild is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the flaw is likely exploitable by sending specially crafted requests to the restConnector endpoint, though the exact exploitation path is not detailed in the advisory; this inference is drawn from the requirement that the feature be enabled for the vulnerability to manifest.
OpenCVE Enrichment