Demonstrating CVE-2020-4448: An RCE Bug in IBM WebSphere Deployment Manager

Опубликовано: 29 Сентябрь 2020
на канале: Zero Day Initiative
2,060
28

This video demonstrates a code execution bug in the IBM WebSphere deployment manager. The specific flaw exists within the BroadcastMessageManager class. The issue results from the lack of proper validation of user-supplied data, which can result in the deserialization of untrusted data.

For full details on the bug used in this video, read the blog at:
https://www.zerodayinitiative.com/blo...