CVE-2020-4163: High severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
Other sources
IBM WebSphere Application Server, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4163?
CVE-2020-4163 is classified as a medium severity vulnerability.
How do I fix CVE-2020-4163?
To fix CVE-2020-4163, update your IBM WebSphere Application Server to the latest available version.
What versions of WebSphere Application Server are affected by CVE-2020-4163?
CVE-2020-4163 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
What type of vulnerability is CVE-2020-4163?
CVE-2020-4163 is a file upload vulnerability that allows authenticated users to execute arbitrary JSP content.
Who is the vendor for the CVE-2020-4163 vulnerability?
The vendor for CVE-2020-4163 is IBM, specifically related to the WebSphere Application Server.