cbcvebase.
CVE-2020-4463
published 2020-07-29

CVE-2020-4463: IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…

PriorityP185high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
31.59%
98.1th percentile
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmmaximo_asset_management
ibmmaximo_asset_management

Detection & IOCsextracted from sources · hover to see the quote

url/os/mxperson
url/meaweb/os/mxperson
otherhttp.favicon.hash:-399298961
othericon_hash=-399298961
  • Exploit uses HTTP POST with Content-Type: application/xml to the /os/mxperson or /meaweb/os/mxperson endpoints; a vulnerable response will contain both 'QueryMXPERSONResponse' and 'MXPERSONSet' in the body, and 'application/xml' in the response header.
  • IBM Maximo Asset Management instances can be fingerprinted via Shodan favicon hash -399298961 or FOFA icon_hash=-399298961 to identify potential targets.
  • Attack vector is unauthenticated (PR:N, UI:N) remote POST request carrying a malicious XML payload to the Maximo REST/MEA web service endpoint.
  • ·Vulnerability affects IBM Maximo Asset Management versions 7.6.0.1 and 7.6.0.2 only; other versions are not confirmed vulnerable.
  • ·The Nuclei template targets two distinct deployment paths (/os/mxperson and /meaweb/os/mxperson); detection logic requires both response body keywords AND application/xml header to confirm exploitation, reducing false positives.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vulncheck8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.