
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM WebSphere Application Server versions 8.0, 8.5, and 9.0 were identified as vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. The vulnerability, tracked as CVE-2021-20453, was discovered and reported by researchers from Cloud-Penetrating Arrow Lab and Knownsec 404 Team. The initial disclosure was made on April 19, 2021 (IBM Security).
The vulnerability received a CVSS Base score of 8.2, with a vector string of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L. The attack vector is network-based, requires low attack complexity, needs no privileges, and requires no user interaction. The scope is unchanged, with high impact on confidentiality and low impact on availability (IBM Security).
If exploited, this vulnerability could allow remote attackers to expose sensitive information or consume memory resources in affected systems. The vulnerability affects multiple platforms including AIX, HP-UX, IBM i, Linux, Solaris, Windows, and z/OS operating systems (IBM Security).
The vulnerability is externally exploitable through network access, requiring low complexity to execute. No specific instances of exploitation in the wild were reported in the available sources (IBM Security).
IBM released several remediation options for affected versions. For V9.0.0.0 through 9.0.5.7, users can either upgrade to Fix Pack 9.0.5.8 or later, or apply Interim Fix PH34067. For V8.5.0.0 through 8.5.5.19, the options include upgrading to Fix Pack 8.5.5.20 or later, or applying Interim Fix PH34067. For V8.0.0.0 through 8.0.0.15, users must upgrade to 8.0.0.15 and apply Interim Fix PH34067. No workarounds were provided as alternatives to patching (IBM Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."