CVE-2020-4450
82Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.8epss 34%
from disclosure to weapon712 days
Published on NVDJun 5
1st PoC+712d
VulnCheck+1566d
exploitation probability
34%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short
IBM WebSphere Application Server versions 8.5 and 9.0 can be tricked into running malicious code if an attacker sends specially crafted data. This is dangerous because it gives attackers complete control over the server.
Technical detail
A deserialization vulnerability in IBM WebSphere Application Server 8.5 and 9.0 allows remote code execution when processing untrusted serialized Java objects. The attack requires network access to the application server and results in arbitrary code execution with the privileges of the WebSphere process.
Summary generated and translated by AI from the official description.
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.
CVSS:3.0/UI:N/AV:N/C:H/PR:N/AC:L/I:H/S:U/A:H/RL:O/E:U/RC:C
Affected products
IBM · WebSphere Application Serverpublic PoCs found — 1
vulncheckvulncheck.com/xdb/5a744e3a8a55unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.