CVE-2020-4427
KEVnicheSAML Authentication Bypass Grants Admin Access in IBM Data Risk Manager
CISA: IBM Data Risk Manager Security Bypass Vulnerability
IBM Data Risk Manager versions 2.0.1 through 2.0.6 contain an improper authentication flaw (CWE-287) that allows an unauthenticated remote attacker to bypass security when the appliance is configured for SAML authentication. By sending a specially crafted HTTP request, the attacker can circumvent the authentication process entirely. Successful exploitation yields full administrative access to the system, with high impact on confidentiality, integrity and availability, reflected in the critical 9.8 CVSS score. Only deployments that use SAML authentication are affected; installations using other authentication methods are not exposed to this flaw. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating exploitation in the wild, and EPSS assigns a 70% probability of exploitation within 30 days.
What to do: Apply IBM's update per vendor instructions, as required by CISA's KEV listing; IBM's security bulletin addresses this flaw in Data Risk Manager 2.0.6.1. Until patched, restrict network access to the appliance's management interface and consider temporarily switching from SAML to non-SAML authentication, since only SAML-configured deployments are vulnerable. Verify whether your deployment uses SAML and review appliance logs for unexpected administrative logins or anomalous HTTP requests.
| IBM Data Risk Manager | 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6 (when configured with SAML authentication) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
- Affected
- IBM Data Risk Manager
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ibm
- Products
- data risk manager
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.