CISA Known Exploited Vulnerability

CVE-2020-4430

IBM · Data Risk Manager

IBM Data Risk Manager Directory Traversal Vulnerability

Date added
BOD 22-01 due date
CWE CWE-22
Ransomware Unknown

CISA description

IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.

Required action

Apply updates per vendor instructions.