PT-2020-18078 · Ibm · Ibm Sterling External Authentication Server+1

Published

2020-07-16

·

Updated

2020-07-22

·

CVE-2020-4462

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions IBM Sterling External Authentication Server versions 2.4.2 through 6.0.1 IBM Sterling Secure Proxy versions 3.4.2 through 6.0.1
Description The issue allows for an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to expose sensitive information or consume memory resources.
Recommendations For IBM Sterling External Authentication Server versions 2.4.2 through 6.0.1, update to a version that includes a fix for the XML External Entity Injection issue. For IBM Sterling Secure Proxy versions 3.4.2 through 6.0.1, update to a version that includes a fix for the XML External Entity Injection issue.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4462

Affected Products

Ibm Sterling External Authentication Server
Ibm Sterling Secure Proxy