Directory Traversal Vulnerability in IBM Data Risk Manager
CVE-2020-4430

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
7 May 2020

Badges

👾 Exploit Exists🟣 EPSS 95%🦅 CISA Reported

Summary

IBM Data Risk Manager versions 2.0.1 through 2.0.4 are susceptible to a directory traversal vulnerability that allows remote authenticated attackers to craft specific URL requests. These requests may enable attackers to access and download arbitrary files from the system, potentially exposing sensitive information. It is critical for administrators to manage and mitigate this risk to safeguard their systems from unauthorized file access.

CISA Reported

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply updates per vendor instructions.

Affected Version(s)

Data Risk Manager 2.0.1

Data Risk Manager 2.0.2

Data Risk Manager 2.0.3

References

EPSS Score

95% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.