CVE-2020-4450
published 2020-06-05CVE-2020-4450: IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted…
PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
33.94%
98.2th percentile
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.18 | 8.5.5.18 |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.5 | 9.0.5.5 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvf6-4v5x-94mq: IBM WebSphere Application Server 8
ghsa_unreviewed·2022-05-24
CVE-2020-4450 [HIGH] GHSA-fvf6-4v5x-94mq: IBM WebSphere Application Server 8
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
VulnCheck
IBM websphere_application_server Deserialization of Untrusted Data
vulncheck·2020·CVSS 9.8
CVE-2020-4450 [CRITICAL] IBM websphere_application_server Deserialization of Untrusted Data
IBM websphere_application_server Deserialization of Untrusted Data
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
Affected: IBM websphere_application_server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF
Exploit PoC: https://vulncheck.com/xdb/5a744e3a8a55
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/181231https://www.ibm.com/support/pages/node/6220294https://www.zerodayinitiative.com/advisories/ZDI-20-689/https://exchange.xforce.ibmcloud.com/vulnerabilities/181231https://www.ibm.com/support/pages/node/6220294https://www.zerodayinitiative.com/advisories/ZDI-20-689/
2020-06-05
Published
Exploited in the wild