CVE-2019-4720: IBM WebSphere Application Server

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.

Affected products

  • IBM WebSphere Application Server: before 20.0.0.2 (fixed in 20.0.0.2); from 7.0.0.0, up to and including 7.0.0.45; from 8.0.0.0, up to and including 8.0.0.15; from 8.5.0.0, up to and including 8.5.5.17; from 9.0.0.0, up to and including 9.0.5.2

Published 2020-01-31. Last modified 2026-06-17.