IBM Support

PH26952:IBM WebSphere Application Server SOAP Deserialization Vulnerability (CVE-2020-4464 CVSS score 8.8)

Download


Downloadable File

File link File size File description

Abstract

IBM WebSphere Application Server SOAP Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2020-4464 CVSS score 8.8)

Download Description

PH26952 resolves the following problem:
IBM WebSphere Application Server SOAP Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2020-4464  CVSS score 8.8)


ERROR DESCRIPTION:
IBM WebSphere Application Server SOAP Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2020-4464  CVSS score 8.8)

LOCAL FIX:

PROBLEM SUMMARY:
IBM WebSphere Application Server SOAP Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2020-4464  CVSS score 8.8)

PROBLEM CONCLUSION:
IBM WebSphere Application Server SOAP Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2020-4464  CVSS score 8.8)

Prerequisites

Download the UpdateInstaller below to install this fix.

URL SIZE(Bytes)
UpdateInstaller 7250000
Install the following fix prior to installing this fix.

Installation Instructions

Review the readme.txt for detailed installation instructions.

URL SIZE(Bytes)
V70 Readme 5342
V80 Readme 2652
V85 Readme 2696
V90 Readme 2477

Download Package

DOWNLOAD RELEASE DATE SIZE(Bytes)

DOWNLOAD Options

What is Fix Central(FC)?

7.0.0.45-WS-WAS-IFPH26952 16 July 2020 8753 FC
8.0.0.15-WS-WAS-IFPH26952 16 July 2020 258528 FC
8.5.5.14-WS-WAS-IFPH26952 16 July 2020 263404 FC
9.0.5.3-WS-WAS-IFPH26952 16 July 2020 260434 FC

Problems Solved

PH26952

On

Technical Support

Contact IBM Support at https://www.ibm.com/software/mysupport/s/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"General","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"7.0.0.45;8.0.0.15;8.5.5.14;8.5.5.15;8.5.5.16;8.5.5.17;9.0.5.3;9.0.5.4","Edition":"Network Deployment,Base","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 July 2020

UID

ibm16249987