Executive brief
IBM WebSphere Application Server and WebSphere Liberty are affected by a security flaw in their web server plug-ins. This vulnerability allows an attacker to manipulate how the server interprets web requests, potentially leading to unauthorized access to sensitive data or the ability to bypass security controls. Organizations using these plug-ins should apply the available security updates to prevent attackers from interfering with web traffic.
Technical details
IBM WebSphere Application Server and WebSphere Liberty are vulnerable to HTTP request smuggling (CWE-444) within the Web Server Plug-ins component. The vulnerability arises from inconsistent interpretation of HTTP requests between the plug-in and the backend server. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the server. Successful exploitation could allow an attacker to bypass security constraints, access sensitive information, or poison web caches. The vulnerability is addressed by applying interim fix PH71342 or upgrading to fix packs 9.0.5.28 and 8.5.5.30 or later.
Affected products
- IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5.0.0 - 8.5.5.29, 9.0.0.0 - 9.0.5.27
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched: Interim fix PH71342 released