CVE-2020-6937: High severity wibu codemeter runtime vulnerability
Published May 29, 2020
·Updated
A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.
Affected Software
6 affected components
MuleSoft Mule Runtime>=3.8.0<=3.8.7
MuleSoft Mule Runtime>=3.8.0<=3.8.7
MuleSoft Mule Runtime>=3.9.0<=3.9.4
MuleSoft Mule Runtime>=3.9.0<=3.9.4
MuleSoft Mule Runtime>=4.0.0<=4.3.0
MuleSoft Mule Runtime>=4.0.0<=4.3.0
Event History
May 29, 2020
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-6937?
CVE-2020-6937 has been classified as a Denial of Service vulnerability.
2
How do I fix CVE-2020-6937?
To fix CVE-2020-6937, upgrade your MuleSoft Mule runtime to a version released after April 7, 2020.
3
Which versions of MuleSoft are affected by CVE-2020-6937?
CVE-2020-6937 affects MuleSoft Mule CE/EE versions 3.8.x, 3.9.x, and 4.x released before April 7, 2020.
4
Can CVE-2020-6937 be exploited remotely?
Yes, CVE-2020-6937 can be exploited by remote attackers to submit data that leads to resource exhaustion.
5
Is there a workaround for CVE-2020-6937?
There are no official workarounds for CVE-2020-6937; upgrading to a patched version is the recommended action.