CVE-2020-4643: XEE
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information. IBM X-Force ID: 185590.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4643?
CVE-2020-4643 is considered a high severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2020-4643?
To fix CVE-2020-4643, upgrade your IBM WebSphere Application Server to the latest version that patches the vulnerability.
Which versions of IBM WebSphere Application Server are affected by CVE-2020-4643?
CVE-2020-4643 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 up to certain patch levels.
What type of attack is exploited by CVE-2020-4643?
CVE-2020-4643 is exploited through an XML External Entity Injection (XXE) attack.
Can CVE-2020-4643 be exploited remotely?
Yes, CVE-2020-4643 can be exploited remotely by an attacker with the ability to send malicious XML data.