Executive brief
IBM WebSphere Application Server, a platform used to build and run enterprise applications, is vulnerable to a security flaw that could allow an attacker to interfere with web traffic. By sending specially crafted requests, an attacker could bypass security controls or gain unauthorized access to sensitive data by 'smuggling' hidden commands past security filters. This could lead to the compromise of user sessions or the modification of application data.
Technical details
IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to HTTP request smuggling (CWE-444). The vulnerability arises from the improper handling of HTTP TRACE requests when specific servlet features (3.0 through 6.1) are enabled. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the server, potentially leading to the bypass of security constraints, cache poisoning, or session hijacking. The attack requires high complexity, likely due to the need for specific timing or front-end proxy configurations to successfully 'smuggle' the request. Remediation is available via interim fixes PH72191 and PH72192, or by upgrading to fix packs 26.0.0.8, 9.0.5.29, or 8.5.5.31.
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched