CVE-2020-4448 is a critical remote code execution vulnerability affecting IBM WebSphere Application Server Network Deployment versions 7.0, 8.0, 8.5, and 9.0. An unauthenticated remote attacker can exploit this deserialization flaw by sending specially crafted serialized objects to execute arbitrary code on the system. With a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and allows for complete compromise of confidentiality, integrity, and availability. While not currently listed on the KEV catalog, its high FAUCET Risk Score of 92/100 and community discussion indicate significant concern. There is no public exploit code available via Metasploit, Nuclei, or ExploitDB, but it has received media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5.0.0, < 8.5.5.18CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* | ||
>= 9.0.0.0, < 9.0.5.4CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_virtual_enterprise:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_virtual_enterprise:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.