ZeroHour

CVE-2020-4430

KEVniche

Authenticated Directory Traversal in IBM Data Risk Manager 2.0.x

CISA: IBM Data Risk Manager Directory Traversal Vulnerability

CVSS 3.1
4.3 medium
EPSS
69%p99
Published
()
KEV added
AI analysis

IBM Data Risk Manager versions 2.0.1 through 2.0.4 contain a directory traversal flaw (CWE-22) that allows a remote, authenticated attacker to send a specially crafted URL request and download arbitrary files from the server. The flaw is triggered by an authenticated user with low privileges submitting a crafted URL, requires no user interaction, and is network-exploitable with low attack complexity. Successful exploitation grants read access to arbitrary files on the system, potentially exposing configuration data or credentials, with confidentiality-only impact per the CVSS 4.3 score. Any organization running IBM Data Risk Manager 2.0.1-2.0.4, especially instances with the management interface reachable from untrusted networks, is affected. The vulnerability is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 68.5% EPSS probability of exploitation in the next 30 days, though no public proof-of-concept is known.

What to do: Apply the vendor update per IBM's advisory to move off the affected 2.0.1-2.0.4 releases, as required by the CISA KEV catalog. Until patched, restrict access to the Data Risk Manager interface to trusted networks and review access logs for crafted URL requests indicative of arbitrary-file-download attempts. Confirm whether your appliance is internet-exposed, and treat downloaded-file access as a potential credential or configuration disclosure.

Affected
IBM Data Risk Manager2.0.1, 2.0.2, 2.0.3, and 2.0.4
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (estimate; no published install-base counts) — IBM Data Risk Manager is a specialized enterprise risk-management appliance with no public active-install or market-share data, so the installed base is estimated from the typically small, per-organization deployment pattern of this niche…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.

CISA Known Exploited Vulnerability
Affected
IBM Data Risk Manager
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
ibm
Products
data risk manager
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.