CVE-2020-4427

Confirmed PUBLISHED

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured...

IBM · Data Risk Manager
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 70.0%

At a Glance

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

nuclei_scanner metasploit cisa
CVE Published
May 07, 2020
Exploitation Reported
Nov 03, 2021
CVSS
9.8 Critical
EPSS
70.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
IBM
Data Risk Manager

2.0.1

Affected
IBM
Data Risk Manager

2.0.2

Affected
IBM
Data Risk Manager

2.0.3

Affected
IBM
Data Risk Manager

2.0.4

Affected
IBM
Data Risk Manager

2.0.5

Affected
IBM
Data Risk Manager

2.0.6

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.