cbcvebase.
CVE-2020-4448
published 2020-06-05

CVE-2020-4448: IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a…

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.22%
95.7th percentile
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.

Affected

8 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server>= 8.5.0.0 < 8.5.5.188.5.5.18
ibmwebsphere_application_server>= 9.0.0.0 < 9.0.5.49.0.5.4
ibmwebsphere_virtual_enterprise
ibmwebsphere_virtual_enterprise

Detection & IOCsextracted from sources · hover to see the quote

port11006
  • Monitor for unexpected inbound TCP connections to port 11006, which is the WebSphere Extended Deployment administrative communications port targeted by CVE-2020-4448.
  • Detect exploitation attempts by monitoring for Broadcast messages invoking the UploadFileToAllNodes BroadcastMessageProcessor, particularly those containing directory traversal sequences in file paths.
  • Alert on attacker-controlled selection of BroadcastMessageProcessor class in messages received on port 11006, as the protocol allows the sender to specify which processor handles the message.
  • ·CVE-2020-4448 only affects WebSphere Application Server Network Deployment installations where a deployment manager profile has been created using the deployment manager profile template; standalone WAS installs are not affected.
  • ·IBM's fix for CVE-2020-4448 fully deprecated the file upload functionality (UploadFileToAllNodes), so patched systems will no longer expose this attack surface.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.