CVE-2026-11710: IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability
IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
Other sources
IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional (8.5)to a version that resolves this vulnerability.Fixed in 8.5.5.31Patch PH71679
Event History
Frequently Asked Questions
What must an attacker be able to do to exploit this issue?
The vulnerability is remotely reachable over the network and does not require authentication or user interaction. Exploitation has high attack complexity.
Which security properties can be affected?
Successful exploitation can have a high impact on confidentiality and a low impact on integrity. No availability impact is indicated.
Which deployment is identified as affected?
The provided information identifies IBM WebSphere Application Server 8.5 as affected. No information is provided about other versions, default configurations, mitigations, or detection methods.