CVE-2021-20454: XEE
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196649.
Other sources
IBM WebSphere Application Server is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20454?
CVE-2021-20454 is a vulnerability in IBM WebSphere Application Server that allows for XML External Entity Injection (XXE) attacks.
What is the severity of CVE-2021-20454?
The severity of CVE-2021-20454 is rated as high with a CVSS score of 8.2.
Which versions of IBM WebSphere Application Server are affected by CVE-2021-20454?
IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 are affected by CVE-2021-20454.
How does CVE-2021-20454 impact the affected software?
CVE-2021-20454 allows remote attackers to exploit the vulnerability and potentially expose sensitive information or consume memory resources.
Where can I find more information about CVE-2021-20454?
More information about CVE-2021-20454 can be found at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/196649) and [Reference 2](https://www.ibm.com/support/pages/node/6445481).