CVE-2020-4576: High severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.
Other sources
IBM WebSphere Application Server traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4576?
CVE-2020-4576 is rated with a high severity due to its potential to expose sensitive information to remote attackers.
How do I fix CVE-2020-4576?
To fix CVE-2020-4576, upgrade your IBM WebSphere Application Server to a version that is not vulnerable, specifically above the fixed version for your current release.
Which versions of IBM WebSphere Application Server are affected by CVE-2020-4576?
CVE-2020-4576 affects IBM WebSphere Application Server versions 7.5, 8.0, 8.5, and 9.0 up to specific patch levels.
What types of attacks can CVE-2020-4576 enable?
CVE-2020-4576 can enable remote attackers to gain access to sensitive information through crafted serialized objects.
Is there a workaround for CVE-2020-4576 until I can apply a patch?
Implementing strict access controls to the affected application can serve as a temporary workaround for CVE-2020-4576.