Lucene search

K
ibmIBMC9C4235C34E1A436F6973E926458F8E4E760EA8C85112E0BC1C3CC10E448DFA5
HistoryApr 27, 2022 - 10:23 a.m.

Security Bulletin: Security vulnerabilities have been identified in IBM WebSphere Application Server used by IBM InfoSphere Master Data Management 11.6

2022-04-2710:23:01
www.ibm.com
12
ibm websphere
remote code execution
infosphere mdm

EPSS

0.022

Percentile

89.5%

Summary

IBM WebSphere Application Server 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.

Vulnerability Details

CVEID:CVE-2020-4464
**DESCRIPTION:**IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code on a system with a specially-crafted sequence of serialized objects over the SOAP connector. IBM X-Force ID: 181489.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/181489 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Master Data Management 11.6

Remediation/Fixes

Principal Product and Version(s) Affected Supporting Product and Version Affected Supporting Product Security Bulletin
IBM InfoSphere Master Data Management 11.6
IBM WebSphere Application Server versions 9.0.

Security Bulletin: WebSphere Application Server is vulnerable to a remote code execution vulnerability (CVE-2020-4464)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibminfosphere_master_data_managementMatch11.6
VendorProductVersionCPE
ibminfosphere_master_data_management11.6cpe:2.3:a:ibm:infosphere_master_data_management:11.6:*:*:*:*:*:*:*

EPSS

0.022

Percentile

89.5%

Related for C9C4235C34E1A436F6973E926458F8E4E760EA8C85112E0BC1C3CC10E448DFA5