CVE-2021-20492: XEE
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197793.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20492?
CVE-2021-20492 is a vulnerability in IBM WebSphere Application Server and Liberty Java Batch that allows for an XML External Entity (XXE) injection attack, potentially exposing sensitive information or consuming memory resources.
Who is affected by CVE-2021-20492?
Users of IBM WebSphere Application Server versions 8.0, 8.5, 9.0, and Liberty Java Batch versions 17.0.0.3 to 21.0.0.5 are affected by CVE-2021-20492.
What is the severity of CVE-2021-20492?
CVE-2021-20492 has a severity rating of 8.2 (high).
How can an attacker exploit CVE-2021-20492?
An attacker can exploit CVE-2021-20492 by injecting malicious XML data to perform an XML External Entity (XXE) attack, potentially exposing sensitive information or consuming memory resources.
Is there a fix for CVE-2021-20492?
IBM has released security updates to address CVE-2021-20492. It is recommended to update to the latest version of IBM WebSphere Application Server or Liberty Java Batch to mitigate this vulnerability.