#VU45825 Deserialization of untrusted data in IBM WebSphere Application Server - CVE-2020-4589
Published: August 20, 2020
IBM WebSphere Application Server
IBM Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
The vulnerability only occurs if an undocumented customization has been applied by an administrator.