IBM Support

PH26354: WebSphere Application Server is vulnerable to cross-site scripting (CVE-2020-4575)

Download


Downloadable File

File link File size File description

Abstract

WebSphere Application Server is vulnerable to cross-site scripting (CVE-2020-4575. CVSS score 4.7)

For WebSphere Virtual Enterprise version 8.0.0.15, apply 7.0.0.1-WS-WVE-IFPH26354.
For WebSphere Virtual Enterprise version 7.0.0.45, apply 7.0.0.0-WS-WVEWAS7-IFPH26354.

Download Description

PH26354 resolves the following problem:

ERROR DESCRIPTION:
WebSphere Application Server is vulnerable to cross-site scripting (CVE-2020-4575. CVSS score 4.7)

LOCAL FIX:


PROBLEM SUMMARY:
WebSphere Application Server is vulnerable to cross-site scripting (CVE-2020-4575. CVSS score 4.7)

PROBLEM CONCLUSION:
WebSphere Application Server is vulnerable to cross-site scripting (CVE-2020-4575. CVSS score 4.7)
This fix is included in fix packs 8.5.5.18 and 9.0.5.5

Prerequisites

None

Installation Instructions

Review the readme.txt for detailed installation instructions.

URL SIZE(Bytes)
V85 Readme 2615
V90 Readme 2502

Download Package

DOWNLOAD RELEASE DATE SIZE(Bytes)

DOWNLOAD Options

What is Fix Central(FC)?

9.0.0.0-WS-WASND-IFPH26354  
(9.0.0.0 - 9.0.5.4)
26 August 2020 394939 FC
8.5.5.0-WS-WASND-IFPH26354  
(8.5.5.0 - 8.5.5.17)
26 August 2020 396831 FC
7.0.0.1-WS-WVE-IFPH26354
(For WebSphere Virtual Enterprise version 8.0.0.15)
26 August 2020 279990 FC
7.0.0.0-WS-WVEWAS7-IFPH26354
(For WebSphere Virtual Enterprise version 7.0.0.45)
26 August 2020 125849 FC

Problems Solved

PH26354

On

Technical Support

Contact IBM Support at https://www.ibm.com/software/mysupport/s/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"General","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.5.5;8.5.5.1;8.5.5.10;8.5.5.11;8.5.5.12;8.5.5.13;8.5.5.14;8.5.5.15;8.5.5.16;8.5.5.17;8.5.5.2;8.5.5.3;8.5.5.4;8.5.5.5;8.5.5.6;8.5.5.7;8.5.5.8;8.5.5.9;9.0.0.0;9.0.0.1;9.0.0.10;9.0.0.11;9.0.0.2;9.0.0.3;9.0.0.4;9.0.0.5;9.0.0.6;9.0.0.7;9.0.0.8;9.0.0.9;9.0.5.0;9.0.5.1;9.0.5.2;9.0.5.3;9.0.5.4","Edition":"Network Deployment","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
26 August 2020

UID

ibm16261017