CVE-2020-4428
KEVnicheAuthenticated Command Injection RCE in IBM Data Risk Manager 2.0.x
CISA: IBM Data Risk Manager Remote Code Execution Vulnerability
IBM Data Risk Manager versions 2.0.1, 2.0.2, 2.0.3 and 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote attacker who has already authenticated to the appliance execute arbitrary commands. Because the CVSS vector rates privileges required as high, triggering the flaw requires privileged, administrator-level credentials to the product, after which the injected commands run outside the application context on the underlying appliance operating system (scope is changed per the CVSS vector). Successful exploitation yields full compromise of the host, with high impact to confidentiality, integrity and availability. Any organization running Data Risk Manager 2.0.1 through 2.0.4 is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, EPSS puts its 30-day exploitation probability at roughly 62% (99th percentile), and no public proof-of-concept is known.
What to do: Upgrade every Data Risk Manager deployment running 2.0.1, 2.0.2, 2.0.3 or 2.0.4 to the fixed release per IBM's security bulletin, as this is the required action under CISA's KEV listing. Because exploitation requires high-privileged credentials, review and rotate appliance administrator credentials and hunt for signs of unexpected command execution on the appliance host. Restrict the appliance's management interface to trusted administrative networks rather than exposing it to the internet.
| IBM Data Risk Manager | 2.0.1, 2.0.2, 2.0.3, 2.0.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
- Affected
- IBM Data Risk Manager
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ibm
- Products
- data risk manager
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.