← back
CVE-2020-4450criticalobserved exploitation

CVE-2020-4450

82Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.8epss 34%
from disclosure to weapon712 days
Published on NVDJun 5
1st PoC+712d
VulnCheck+1566d
exploitation probability
34%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short

IBM WebSphere Application Server versions 8.5 and 9.0 can be tricked into running malicious code if an attacker sends specially crafted data. This is dangerous because it gives attackers complete control over the server.

Technical detail

A deserialization vulnerability in IBM WebSphere Application Server 8.5 and 9.0 allows remote code execution when processing untrusted serialized Java objects. The attack requires network access to the application server and results in arbitrary code execution with the privileges of the WebSphere process.

Summary generated and translated by AI from the official description.
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
CVSS:3.0/UI:N/AV:N/C:H/PR:N/AC:L/I:H/S:U/A:H/RL:O/E:U/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.