CVE-2026-15325: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72191
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15325?
CVE-2026-15325 has a severity rating of 8.7, indicating a high risk.
How do I fix CVE-2026-15325?
To fix CVE-2026-15325, upgrade to the latest version of IBM WebSphere Application Server or WebSphere Application Server Liberty as specified in the advisory.
What types of applications are affected by CVE-2026-15325?
CVE-2026-15325 affects IBM WebSphere Application Server versions 8.5 and 9.0, as well as IBM WebSphere Application Server - Liberty between versions 17.0.0.3 and 26.0.0.7.
What kind of vulnerability is CVE-2026-15325?
CVE-2026-15325 is classified as an HTTP request smuggling vulnerability due to improper handling of TRACE requests.
What impact does CVE-2026-15325 have on my system?
CVE-2026-15325 can lead to unauthorized data exposure and manipulation, potentially compromising the integrity and confidentiality of the application.