CVE-2026-15325

IBM · WebSphere Application Server

IBM WebSphere Application Server is vulnerable to HTTP request smuggling due to inconsistent interpretation of HTTP requests, potentially allowing an unauthenticated attacker to bypass security controls.

Executive summary

An unauthenticated attacker can exploit HTTP request smuggling in IBM WebSphere Application Server to compromise sensitive data and integrity.

Vulnerability

This vulnerability involves CWE-444, where the application improperly handles HTTP requests, allowing an unauthenticated attacker to manipulate how requests are processed by front-end and back-end systems.

Business impact

The vulnerability carries a CVSS score of 8.7, reflecting its high potential for severe impact. Successful exploitation could lead to unauthorized access to sensitive information and modification of data, potentially allowing an attacker to impersonate legitimate users or bypass application firewalls.

Remediation

Immediate Action: Apply the vendor-provided interim fix or fix pack that resolves APAR PH72191 or PH72192 immediately.

Proactive Monitoring: Review web server access logs for anomalous request patterns or unexpected HTTP status codes that may indicate smuggling attempts.

Compensating Controls: Ensure that front-end load balancers or proxy servers are configured to normalize HTTP requests and reject non-compliant traffic.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the severity of this vulnerability, organizations must prioritize the application of the specified IBM patches. Failure to remediate this issue exposes the application environment to sophisticated request manipulation attacks that can bypass perimeter security.