CVE-2020-4462: XEE
IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181482.
Other sources
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4462?
CVE-2020-4462 is a vulnerability in IBM Sterling External Authentication Server and IBM Sterling Secure Proxy that allows for an XML External Entity Injection (XXE) attack.
How can this vulnerability be exploited?
This vulnerability can be exploited remotely by sending malicious XML data, resulting in exposure of sensitive information.
What is the severity of CVE-2020-4462?
The severity of CVE-2020-4462 is high, with a CVSS score of 8.2.
Which versions of IBM Sterling External Authentication Server are affected?
IBM Sterling External Authentication Server versions 2.4.2, 2.4.3.2, 6.0.0, and 6.0.1 are affected.
How can I fix CVE-2020-4462?
To fix CVE-2020-4462, apply the appropriate patches provided by IBM for the affected versions of IBM Sterling External Authentication Server and IBM Sterling Secure Proxy.