CVE-2020-4365: SSRF
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 178964.
Other sources
IBM WebSphere Application Server is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4365?
CVE-2020-4365 is a vulnerability in IBM WebSphere Application Server that allows a remote authenticated attacker to obtain sensitive data.
How does CVE-2020-4365 affect IBM WebSphere Application Server?
CVE-2020-4365 affects IBM WebSphere Application Server versions 8.5.0.0 to 8.5.5.17.
How severe is CVE-2020-4365?
CVE-2020-4365 has a severity rating of 5.3 (medium).
How can an attacker exploit CVE-2020-4365?
An attacker can exploit CVE-2020-4365 by sending a specially crafted request to the server and performing server-side request forgery.
Is IBM WebSphere Application Server the only affected software?
No, IBM WebSphere Application Server is the only affected software by CVE-2020-4365.