CVSS v3
8.2
HIGH
EPSS Score
90.0%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.
Active exploitation of CVE-2020-4463 has not been confirmed. The EPSS score is 90.0%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2020-4463 has a CVSS v3 base score of 8.2 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).