CVE-2020-4449: IBM WebSphere Application Server IIOP Deserialization of Untrusted Data Information Disclosure Vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181230.
Other sources
IBM WebSphere Application Server traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects.
— IBM
This vulnerability allows remote attackers to disclose sensitive information on affected installations of IBM WebSphere. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the IIOP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to disclose information in the context of root.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4449?
CVE-2020-4449 is a vulnerability that allows remote attackers to disclose sensitive information on affected installations of IBM WebSphere Application Server.
What is the severity of CVE-2020-4449?
CVE-2020-4449 has a severity rating of 7.5, which is considered high.
How does CVE-2020-4449 affect IBM WebSphere Application Server?
CVE-2020-4449 affects versions 7.0.0.0 to 7.0.0.45, 8.0.0.0 to 8.0.0.15, 8.5.0.0 to 8.5.5.17, and 9.0.0.0 to 9.0.5.4 of IBM WebSphere Application Server.
Can CVE-2020-4449 be exploited without authentication?
Yes, authentication is not required to exploit CVE-2020-4449.
How can I patch the vulnerability in IBM WebSphere Application Server?
To patch the vulnerability, you can refer to the following IBM support pages for relevant patches: [Patch for IBM Security Identity Manager Virtual Appliance 7.0.2](http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FTivoli%2FTivoli+Identity+Manager&fixids=7.0.2-ISS-SIM-FP0002&source=SARASA) and [Patch for IBM Security Identity Manager Virtual Appliance 7.0.1](http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FTivoli%2FTivoli+Identity+Manager&fixids=7.0.1-ISS-SIM-FP0014&source=SAR).