CVE-2020-4534: High severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of UNC paths. By scheduling a task with a specially-crafted UNC path, an attacker could exploit this vulnerability to execute arbitrary code with higher privileges. IBM X-Force ID: 182808.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4534?
CVE-2020-4534 has a medium severity rating, allowing local authenticated attackers the potential to escalate privileges.
How do I fix CVE-2020-4534?
To fix CVE-2020-4534, it is recommended to apply the latest patches and updates provided by IBM for WebSphere Application Server.
Who is affected by CVE-2020-4534?
CVE-2020-4534 affects users of IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
Can CVE-2020-4534 be exploited remotely?
No, CVE-2020-4534 can only be exploited by local authenticated attackers with access to the system.
What type of attack does CVE-2020-4534 enable?
CVE-2020-4534 allows an attacker to gain elevated privileges on the system through improperly handled UNC paths.