CVE-2020-4576: IBM WebSphere Application Server
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.
Affected products
- IBM WebSphere Application Server: from 7.0.0.0, before 7.0.0.45 (fixed in 7.0.0.45); from 8.0.0.0, before 8.0.0.15 (fixed in 8.0.0.15); from 8.5.0.0, before 8.5.5.19 (fixed in 8.5.5.19); from 9.0.0.0, before 9.0.5.6 (fixed in 9.0.5.6)
Published 2020-10-01. Last modified 2026-06-17.