CVE-2020-4949: XEE
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4949?
The severity of CVE-2020-4949 is high with a CVSS score of 8.2.
How does CVE-2020-4949 affect IBM WebSphere Application Server?
CVE-2020-4949 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 by making them vulnerable to an XML External Entity Injection (XXE) attack.
What is an XML External Entity Injection (XXE) attack?
XML External Entity Injection (XXE) attack is a type of attack where an attacker can exploit vulnerabilities in XML input parsers to disclose internal files or execute remote code.
What are the potential impacts of CVE-2020-4949?
CVE-2020-4949 can potentially expose sensitive information or consume memory resources on the affected IBM WebSphere Application Server.
How can I fix CVE-2020-4949?
To fix CVE-2020-4949, it is recommended to apply the latest security patches provided by IBM for affected versions of WebSphere Application Server.