VulnerabilityModified
CVE-2020-4463
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
HIGH 8.2EPSS 31.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
- EPSS
- 31.59% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- ibm/maximo asset management
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/181484VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6253953Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/181484VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6253953Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.