CVE-2020-4575: XSS
Published Aug 27, 2020
·Updated
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
Affected Software
4 affected components
IBM WebSphere Application Server Feature Pack for Web Services>=8.5.0.0<8.5.5.18
IBM WebSphere Application Server Feature Pack for Web Services>=9.0.0.0<9.0.5.5
IBM WebSphere Virtual Enterprise=7.0
IBM WebSphere Virtual Enterprise=8.0
Remediation
Patch Available
Event History
Aug 27, 2020
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4575.
2
Which products are affected by this vulnerability?
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are affected.
3
What is the severity level of CVE-2020-4575?
The severity level of CVE-2020-4575 is medium (6.1).
4
How can this vulnerability be exploited?
This vulnerability can be exploited through cross-site scripting when High Availability Deployment Manager is configured.
5
Are there any recommended mitigation steps for CVE-2020-4575?
Yes, IBM has provided recommendations to mitigate this vulnerability. Please refer to the official IBM support page for more information.