Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71679. For IBM WebSphere Application Server traditional: For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack. Additional interim fixes may be available and linked off the interim fix download page.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286731 |
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. | |
| Title | IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability | |
| First Time appeared |
Ibm
Ibm websphere Application Server |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm websphere Application Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-18T19:08:09.672Z
Reserved: 2026-06-08T23:57:43.337Z
Link: CVE-2026-11710
No data.
Status : Received
Published: 2026-09-18T20:17:01.097
Modified: 2026-09-18T20:17:01.097
Link: CVE-2026-11710
No data.
OpenCVE Enrichment
No data.