CVE-2021-20353: IBM WebSphere EDataGraphImpl Deserialization of Untrusted Data Information Disclosure Vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 194882.
Other sources
This vulnerability allows remote attackers to disclose sensitive information on affected installations of IBM WebSphere. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EDataGraphImpl class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to disclose information in the context of root.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-20353.
What is the severity of CVE-2021-20353?
The severity of CVE-2021-20353 is high.
How does the vulnerability impact IBM WebSphere installations?
The vulnerability allows remote attackers to disclose sensitive information on affected installations of IBM WebSphere.
Is authentication required to exploit CVE-2021-20353?
No, authentication is not required to exploit CVE-2021-20353.
How can I fix CVE-2021-20353?
To fix CVE-2021-20353, apply the latest security updates provided by IBM.