CVE-2020-4276: High severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.
Other sources
IBM WebSphere Application Server traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4276?
CVE-2020-4276 has been classified with a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2020-4276?
To fix CVE-2020-4276, you should apply the latest security patches provided by IBM for affected versions of WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2020-4276?
CVE-2020-4276 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 up to their respective latest fix packs.
What type of vulnerability is CVE-2020-4276?
CVE-2020-4276 is a privilege escalation vulnerability that can occur when using token-based authentication over the SOAP connector.
Is CVE-2020-4276 a critical vulnerability in WebSphere Application Server?
Yes, CVE-2020-4276 is considered critical as it allows unauthorized access to administrative functionalities when exploited.