CISA Known Exploited Vulnerability

CVE-2020-4427

IBM · Data Risk Manager

IBM Data Risk Manager Security Bypass Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

Required action

Apply updates per vendor instructions.