CVE-2020-4463
published 2020-07-29CVE-2020-4463: IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…
PriorityP185high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
31.59%
98.1th percentile
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/os/mxperson
url/meaweb/os/mxperson
otherhttp.favicon.hash:-399298961
othericon_hash=-399298961
- →Exploit uses HTTP POST with Content-Type: application/xml to the /os/mxperson or /meaweb/os/mxperson endpoints; a vulnerable response will contain both 'QueryMXPERSONResponse' and 'MXPERSONSet' in the body, and 'application/xml' in the response header.
- →IBM Maximo Asset Management instances can be fingerprinted via Shodan favicon hash -399298961 or FOFA icon_hash=-399298961 to identify potential targets.
- →Attack vector is unauthenticated (PR:N, UI:N) remote POST request carrying a malicious XML payload to the Maximo REST/MEA web service endpoint. ↗
- ·Vulnerability affects IBM Maximo Asset Management versions 7.6.0.1 and 7.6.0.2 only; other versions are not confirmed vulnerable. ↗
- ·The Nuclei template targets two distinct deployment paths (/os/mxperson and /meaweb/os/mxperson); detection logic requires both response body keywords AND application/xml header to confirm exploitation, reducing false positives.
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vulncheck8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh5x-6mg7-gjp9: IBM Maximo Asset Management 7
ghsa_unreviewed·2022-05-24
CVE-2020-4463 [MEDIUM] GHSA-mh5x-6mg7-gjp9: IBM Maximo Asset Management 7
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
VulnCheck
IBM maximo_asset_management Improper Restriction of XML External Entity Reference
vulncheck·2020·CVSS 8.2
CVE-2020-4463 [HIGH] IBM maximo_asset_management Improper Restriction of XML External Entity Reference
IBM maximo_asset_management Improper Restriction of XML External Entity Reference
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
Affected: IBM maximo_asset_management
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-22&host_type=src&vulnerability=cve-2020-4463; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-23&h
No detection rules found.
Nuclei
IBM Maximo Asset Management Information Disclosure - XML External Entity Injection
nuclei·CVSS 8.2
CVE-2020-4463 [HIGH] IBM Maximo Asset Management Information Disclosure - XML External Entity Injection
IBM Maximo Asset Management Information Disclosure - XML External Entity Injection
IBM Maximo Asset Management is vulnerable to an
XML external entity injection (XXE) attack when processing XML data.
A remote attacker could exploit this vulnerability to expose
sensitive information or consume memory resources.
Template:
id: CVE-2020-4463
info:
name: IBM Maximo Asset Management Information Disclosure - XML External Entity Injection
author: dwisiswant0
severity: high
description: |
IBM Maximo Asset Management is vulnerable to an
XML external entity injection (XXE) attack when processing XML data.
A remote attacker could exploit this vulnerability to expose
sensitive information or consume memory resources.
impact: |
The vulnerability can lead to unauthorized access to sensitive informati
No writeups or analysis indexed.
2020-07-29
Published
Exploited in the wild