Junglewise Threat Intelligence

CVE-2020-4427: IBM Data Risk Manager Security Bypass Vulnerability

CVE-2020-4427 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: IBM Data Risk Manager. Vendors: IBM.

Executive brief

IBM Data Risk Manager contains a security bypass vulnerability when configured with SAML authentication. A remote, unauthenticated attacker can send a specially crafted HTTP request to bypass the authentication process and gain full administrative access to the system.

Affected products

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.6.1

Timeline

  • 2020-05-07: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-05-07: patched: IBM released patch information (node/6206875)

Related threats