CVE-2020-4163

Description

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.

Risk Information

Base Score
7.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.415

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-4163,CVE-2019-4670 are fixed in IBM WebSphere 9.0.5.3Windows
Vulnerabilities CVE-2020-4163,CVE-2019-10086,CVE-2019-4505,CVE-2019-4670 are fixed in IBM WebSphere 8.5.5.17Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234