Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for Multiplatforms.
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
IBM · CICS Transaction Gateway for Multiplatforms