CVE-2020-4463
IBM maximo_asset_management Improper Restriction of XML External Entity Reference
Record summary
CVE-2020-4463 has a selected CVSS score of 8.2 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Maximo Asset ManagementBrowse IBM / Maximo Asset Management | CVE List, VulnCheck | 7.6.0.1 | affected |
| 7.6.0.2 | affected |
Proofs of concept
1Repository PoCs
GitHubIbonok/CVE-2020-4463Repository PoCby IbonokStars: 52Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHIBM Maximo Asset Management Information Disclosure - XML External Entity InjectionCVSS 8.2
IBM Maximo Asset Management is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Impact
The vulnerability can lead to unauthorized access to sensitive information or a denial of service.
Remediation
Apply the latest security patches or updates provided by IBM to mitigate the vulnerability.
Source: ProjectDiscovery