CVE-2020-4575Cross-site Scripting in IBM Websphere Application Server

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 67.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 24

Description

IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDibm/websphere_application_server8.5.0.08.5.5.18+1
CVEListV5ibm/websphere_virtual_enterprise7.0, 8.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fqq6-8464-3hrq: IBM WebSphere Application Server ND 82022-05-24
CVEList
CVE-2020-4575: IBM WebSphere Application Server ND 82020-08-27
CVE-2020-4575 — Cross-site Scripting in IBM | cvebase