<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>WebSphere Application Server - Liberty 24.0.0.3 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/websphere-application-server---liberty-24.0.0.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 28 Jul 2026 21:29:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/websphere-application-server---liberty-24.0.0.3/feed.xml" rel="self" type="application/rss+xml"/><item><title>IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)</title><link>https://feed.craftedsignal.io/briefs/2026-07-ibm-websphere-path-injection/</link><pubDate>Tue, 28 Jul 2026 21:29:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-ibm-websphere-path-injection/</guid><description>A path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.</description><content:encoded><![CDATA[<p>IBM has disclosed a path-segment injection vulnerability, identified as CVE-2026-15280, affecting its WebSphere Application Server - Liberty product. Specifically, versions 17.0.0.3 through 26.0.0.8 of the ND Collective Controller component are susceptible. This flaw resides within the collective routing mechanism, allowing an unauthenticated attacker to inject arbitrary path segments. This vulnerability is categorized as CWE-22, &quot;Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'),&quot; and carries a CVSS v3.1 Base Score of 7.5, indicating a high severity risk primarily due to its potential for high confidentiality impact. The vulnerability does not require authentication or user interaction for exploitation and can lead to unauthorized access to sensitive information on the affected server.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An unauthenticated attacker sends a specially crafted HTTP request to a vulnerable IBM WebSphere Application Server - Liberty instance.</li>
<li>The request is directed towards a component utilizing the collective routing mechanism of the server.</li>
<li>The attacker embeds malicious path segments within the request, designed to bypass normal validation.</li>
<li>Due to the path-segment injection vulnerability (CVE-2026-15280), the collective routing mechanism fails to properly sanitize or validate these injected segments.</li>
<li>This failure allows the attacker to manipulate the server's path resolution logic, enabling access to restricted directories or files.</li>
<li>The server processes the request with the injected path, leading to unauthorized disclosure of sensitive information from the file system.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of CVE-2026-15280 can lead to significant information disclosure. Attackers capable of exploiting this path-segment injection vulnerability could gain unauthorized access to critical configuration files, user data, server logs, or other sensitive information stored on the affected IBM WebSphere Application Server - Liberty instances. While the vulnerability does not directly enable integrity modification or availability impact, the exposure of confidential data can have severe consequences, including intellectual property theft, privacy breaches, and further system compromise through credential harvesting or detailed reconnaissance. Organizations using affected versions are at risk of data exfiltration and compliance violations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-15280 immediately by upgrading IBM WebSphere Application Server - Liberty to a fixed version as specified in the IBM Corporation advisory at <code>https://www.ibm.com/support/pages/node/7281633</code>.</li>
<li>Review network logs for unusual HTTP requests targeting the collective routing mechanism or containing atypical path segments, particularly those involving <code>CWE-22</code> characteristics.</li>
<li>Implement strong input validation and sanitization for all user-supplied data, especially in web application path parameters, to prevent future path-segment injection vulnerabilities.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>path-segment-injection</category><category>information-disclosure</category><category>websphere</category><category>ibm</category></item></channel></rss>