Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gmfx-j9mc-3x8v

Опубликовано: 22 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

EPSS

Процентиль: 29%
0.00365
Низкий

7.4 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 7.4
nvd
около 1 месяца назад

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.

EPSS

Процентиль: 29%
0.00365
Низкий

7.4 High

CVSS3

Дефекты

CWE-444