CVE-2020-4575: IBM WebSphere Application Server

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.

Affected products

  • IBM WebSphere Application Server: from 8.5.0.0, before 8.5.5.18 (fixed in 8.5.5.18); from 9.0.0.0, before 9.0.5.5 (fixed in 9.0.5.5)
  • IBM WebSphere Virtual Enterprise: version 7.0 only; version 8.0 only

Published 2020-08-27. Last modified 2026-06-17.