Executive brief
IBM WebSphere Application Server is a platform used to host and manage enterprise Java applications. A vulnerability in its web server plug-in component could allow an attacker to interfere with how the server processes web requests. This can lead to unauthorized access to sensitive information or disruptions to the application's availability.
Technical details
IBM WebSphere Application Server and WebSphere Liberty are vulnerable to HTTP request smuggling (CWE-444) within the Web Server Plug-ins component. The vulnerability is caused by improper validation of input in specially crafted HTTP requests. A remote attacker can exploit this by sending a malicious request that the plug-in interprets differently than the backend server, potentially allowing the attacker to bypass security controls, access sensitive data, or cause a denial of service. The attack requires a high level of complexity to execute successfully. IBM has released interim fixes under APAR PH71342 and recommends upgrading to versions 8.5.5.30 or 9.0.5.28.
Affected products
- IBM Web Server Plug-ins for WebSphere Application Server 8.5.0.0 - 8.5.5.29, 9.0.0.0 - 9.0.5.27
- IBM WebSphere Application Server Liberty 8.5, 9.0
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched