Junglewise Threat Intelligence

CVE-2020-4428: IBM Data Risk Manager Remote Code Execution Vulnerability

CVE-2020-4428 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2021-11-03

Technologies: IBM Data Risk Manager. Vendors: IBM.

Executive brief

IBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to OS command injection. A remote authenticated attacker with high privileges can exploit this vulnerability to execute arbitrary commands on the system.

Affected products

  • IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4

Timeline

  • 2020-05-07: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry

Related threats