CVE-2020-4430
KEVnicheAuthenticated Directory Traversal in IBM Data Risk Manager 2.0.x
CISA: IBM Data Risk Manager Directory Traversal Vulnerability
IBM Data Risk Manager versions 2.0.1 through 2.0.4 contain a directory traversal flaw (CWE-22) that allows a remote, authenticated attacker to send a specially crafted URL request and download arbitrary files from the server. The flaw is triggered by an authenticated user with low privileges submitting a crafted URL, requires no user interaction, and is network-exploitable with low attack complexity. Successful exploitation grants read access to arbitrary files on the system, potentially exposing configuration data or credentials, with confidentiality-only impact per the CVSS 4.3 score. Any organization running IBM Data Risk Manager 2.0.1-2.0.4, especially instances with the management interface reachable from untrusted networks, is affected. The vulnerability is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 68.5% EPSS probability of exploitation in the next 30 days, though no public proof-of-concept is known.
What to do: Apply the vendor update per IBM's advisory to move off the affected 2.0.1-2.0.4 releases, as required by the CISA KEV catalog. Until patched, restrict access to the Data Risk Manager interface to trusted networks and review access logs for crafted URL requests indicative of arbitrary-file-download attempts. Confirm whether your appliance is internet-exposed, and treat downloaded-file access as a potential credential or configuration disclosure.
| IBM Data Risk Manager | 2.0.1, 2.0.2, 2.0.3, and 2.0.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.
- Affected
- IBM Data Risk Manager
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- ibm
- Products
- data risk manager
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.