CVE-2020-4448
published 2020-06-05CVE-2020-4448: IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.22%
95.7th percentile
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 181228.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.18 | 8.5.5.18 |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.4 | 9.0.5.4 |
| ibm | websphere_virtual_enterprise | — | — |
| ibm | websphere_virtual_enterprise | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unexpected inbound TCP connections to port 11006, which is the WebSphere Extended Deployment administrative communications port targeted by CVE-2020-4448. ↗
- →Detect exploitation attempts by monitoring for Broadcast messages invoking the UploadFileToAllNodes BroadcastMessageProcessor, particularly those containing directory traversal sequences in file paths. ↗
- →Alert on attacker-controlled selection of BroadcastMessageProcessor class in messages received on port 11006, as the protocol allows the sender to specify which processor handles the message. ↗
- ·CVE-2020-4448 only affects WebSphere Application Server Network Deployment installations where a deployment manager profile has been created using the deployment manager profile template; standalone WAS installs are not affected. ↗
- ·IBM's fix for CVE-2020-4448 fully deprecated the file upload functionality (UploadFileToAllNodes), so patched systems will no longer expose this attack surface. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Trendmicro
Exploiting Other Remote Protocols in IBM WebSphere
blogs_trendmicro·2020-09-29·CVSS 8.8
[HIGH] Exploiting Other Remote Protocols in IBM WebSphere
## Exploiting Other Remote Protocols in IBM WebSphere
Learn how to exploit other remote protocols in IBM WebSphere.
By: Zero Day Initiative Sep 29, 2020 Read time: ( words)
Save to Folio
In a recent blog post , we disclosed how a vulnerability in the Internet InterORB Protocol (IIOP) protocol of IBM WebSphere can result in remote code execution. In this blog post, we explore how two additional protocols supported by this application server can also be leveraged to achieve the same result. The first is a logic flaw in the authentication mechanism of the wsadmin SOAP endpoint submitted by the researcher known as tint0 ( ZDI-20-878 ), and the second is a vulnerability in a protocol used for WebSphere Extended Deployment reported by b0yd ( ZDI-20-688 )
CVE-2020-4464: SOAP Deserialization
Trendmicro
Exploiting Other Remote Protocols in IBM WebSphere
blogs_trendmicro·2020-09-29·CVSS 8.8
[HIGH] Exploiting Other Remote Protocols in IBM WebSphere
## Exploiting Other Remote Protocols in IBM WebSphere
Learn how to exploit other remote protocols in IBM WebSphere.
By: Zero Day Initiative 2020/09/29 Read time: ( words)
Save to Folio
In a recent blog post , we disclosed how a vulnerability in the Internet InterORB Protocol (IIOP) protocol of IBM WebSphere can result in remote code execution. In this blog post, we explore how two additional protocols supported by this application server can also be leveraged to achieve the same result. The first is a logic flaw in the authentication mechanism of the wsadmin SOAP endpoint submitted by the researcher known as tint0 ( ZDI-20-878 ), and the second is a vulnerability in a protocol used for WebSphere Extended Deployment reported by b0yd ( ZDI-20-688 )
CVE-2020-4464: SOAP Deserialization of
Trendmicro
Exploiting Other Remote Protocols in IBM WebSphere
blogs_trendmicro·2020-09-29·CVSS 8.8
[HIGH] Exploiting Other Remote Protocols in IBM WebSphere
# Exploiting Other Remote Protocols in IBM WebSphere
Learn how to exploit other remote protocols in IBM WebSphere.
By: Zero Day Initiative
2020/09/29
Read time: ( words)
Save to Folio
In a recent blog post, we disclosed how a vulnerability in the Internet InterORB Protocol (IIOP) protocol of IBM WebSphere can result in remote code execution. In this blog post, we explore how two additional protocols supported by this application server can also be leveraged to achieve the same result. The first is a logic flaw in the authentication mechanism of the wsadmin SOAP endpoint submitted by the researcher known as tint0 (ZDI-20-878), and the second is a vulnerability in a protocol used for WebSphere Extended Deployment reported by b0yd (ZDI-20-688)
CVE-2020-4464: SOAP Deserialization of Untr
https://exchange.xforce.ibmcloud.com/vulnerabilities/181228https://www.ibm.com/support/pages/node/6220336https://www.zerodayinitiative.com/advisories/ZDI-20-688/https://exchange.xforce.ibmcloud.com/vulnerabilities/181228https://www.ibm.com/support/pages/node/6220336https://www.zerodayinitiative.com/advisories/ZDI-20-688/
2020-06-05
Published