Record summary

CVE-2020-4463 has a selected CVSS score of 8.2 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheck7.6.0.1affected
7.6.0.2affected

Proofs of concept

1

Repository PoCs

GitHubIbonok/CVE-2020-4463Repository PoCby IbonokStars: 52Not analyzed2 files

8.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHIBM Maximo Asset Management Information Disclosure - XML External Entity InjectionCVSS 8.2

IBM Maximo Asset Management is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Impact

The vulnerability can lead to unauthorized access to sensitive information or a denial of service.

Remediation

Apply the latest security patches or updates provided by IBM to mitigate the vulnerability.

WeaknessesCWE-611
Authorsdwisiswant0
Template tagscvecve2020ibmxxedisclosurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
CPE: cpe:2.3:a:ibm:maximo_asset_management:7.6.0.1:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-399298961
FOFA: icon_hash=-399298961

Source: ProjectDiscovery

References

3