CVE-2020-4462
Summary
| CVE | CVE-2020-4462 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-16 15:15:00 UTC |
| Updated | 2020-07-22 15:37:00 UTC |
| Description | IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181482. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Sterling External Authentication Server | 2.4.2.0 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 2.4.3.2 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 6.0.0.0 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 6.0.1.0 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 2.4.2.0 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 2.4.3.2 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 6.0.0.0 | All | All | All |
| Application | Ibm | Sterling External Authentication Server | 6.0.1.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.2.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.3.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 6.0.0.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 6.0.1.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.2.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 3.4.3.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 6.0.0.0 | All | All | All |
| Application | Ibm | Sterling Secure Proxy | 6.0.1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: XML External Entity Injection (XXE) Vulnerability Affects IBM Secure Proxy (CVE-2020-4462) | CONFIRM | www.ibm.com | Vendor Advisory |
| Security Bulletin: XML External Entity Injection (XXE) Vulnerability Affects IBM Secure External Authentication Server (CVE-2020-4462) | CONFIRM | www.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.