
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-5016 is a directory traversal vulnerability affecting IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0. The vulnerability was disclosed on March 9, 2021, and allows remote attackers to traverse directories on the system when application security is disabled and JAX-RPC applications are present (IBM Advisory).
The vulnerability occurs when application security is disabled and JAX-RPC applications are present. An attacker can exploit this by sending specially-crafted URL requests containing 'dot dot' sequences (/../) to view arbitrary XML files on the system. The vulnerability has been assigned a CVSS Base score of 5.3 (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N), indicating moderate severity with network attack vector and high complexity (IBM Advisory).
If successfully exploited, this vulnerability allows attackers to view arbitrary XML files on the affected system, potentially exposing sensitive information. The impact is limited to confidentiality with no effect on integrity or availability of the system (IBM Advisory).
The vulnerability requires the attacker to have network access and can only be exploited when application security is disabled and JAX-RPC applications are present. The attack complexity is considered high, and low privileges are required for exploitation (IBM Advisory).
IBM has released fixes for all affected versions. For V9.0.0.0 through 9.0.5.6, users can either upgrade to Fix Pack 9.0.5.7 or later, or apply Interim Fix PH33037. For V8.5.0.0 through 8.5.5.19, users can upgrade to Fix Pack 8.5.5.20 or later, or apply Interim Fix PH33037. For V8.0.0.0 through 8.0.0.15 and V7.0.0.0 through 7.0.0.45, users must upgrade to the latest version and apply Interim Fix PH33037. Additionally, ensuring application security is enabled prevents this vulnerability (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."