CVE-2020-4246: XEE
IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 175481.
Other sources
IBM Security Identity Governance Virtual Appliance is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4246.
What is the severity of CVE-2020-4246?
The severity of CVE-2020-4246 is high with a CVSS score of 7.1.
Which software is affected by CVE-2020-4246?
IBM Security Identity Governance and Intelligence version 5.2.6 is affected by CVE-2020-4246.
What is the risk of CVE-2020-4246?
CVE-2020-4246 poses a risk of XML External Entity Injection (XXE) attack, which can expose sensitive information or consume memory resources.
Where can I find more information about CVE-2020-4246?
You can find more information about CVE-2020-4246 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/175481), [Reference 2](https://www.ibm.com/support/pages/node/6207902).