CVE-2020-4682: Critical severity ibm websphere mq light vulnerability
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.
Other sources
IBM MQ could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4682?
The severity of CVE-2020-4682 is high with a score of 8.1.
How does CVE-2020-4682 impact IBM MQ?
CVE-2020-4682 allows a remote attacker to execute arbitrary code on the system.
How can a remote attacker exploit CVE-2020-4682?
A remote attacker can exploit CVE-2020-4682 by performing an unsafe deserialization of trusted data.
What is the affected software for CVE-2020-4682?
IBM MQ versions 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD are affected by CVE-2020-4682.
Is there a fix available for CVE-2020-4682?
Yes, IBM has provided a fix for CVE-2020-4682. Please refer to the IBM support page for more information.