CyberRota Analysis
AI-GeneratedIBM WebSphere Application Server versions 9.0 and 8.5, along with WebSphere Application Server - Liberty, are susceptible to HTTP request smuggling due to improper parsing of the HTTP transfer-encoding request header. This vulnerability allows attackers to potentially poison the web cache, bypass web application firewalls, and execute cross-site scripting (XSS) attacks. Organizations using these versions should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.