cbcvebase.
CVE-2021-20492
published 2021-05-26

CVE-2021-20492: IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data…

high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.

Affected

8 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server17.0.0.3 – 21.0.0.5
ibmwebsphere_application_server8.0.0.0 – 8.0.0.15
ibmwebsphere_application_server8.5.0.0 – 8.5.5.19
ibmwebsphere_application_server9.0.0.0 – 9.0.5.7