HTTP Request Smuggling Vulnerability in IBM WebSphere Application Server
CVE-2026-15325

8.7HIGH

What is CVE-2026-15325?

IBM WebSphere Application Server versions 9.0, 8.5, and Liberty from 17.0.0.3 to 26.0.0.7 are at risk due to a flaw in how TRACE requests are processed, allowing attackers to manipulate the server's request handling. This could lead to unauthorized access or data leakage, making it critical for organizations using these products to address the vulnerability promptly.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.7

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.