Description
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected products
- ibm / web_server_plug_ins_for_websphere_application_server_and_websphere_liberty8.5 – 8.5
- ibm / web_server_plug_ins_for_websphere_application_server_and_websphere_liberty8.5.0 – 8.5.0
- ibm / websphere_application_server8.5.0.0 – 8.5.5.30
- ibm / websphere_application_server8.5.0.0 – 8.5.5.30
References
Updated 10m ago · 8 sources