Vulnerabilities > CVE-2020-4427 - Unspecified vulnerability in IBM Data Risk Manager

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
ibm
critical
metasploit

Summary

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

Metasploit

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/157567/ibm_drm_rce.rb.txt
idPACKETSTORM:157567
last seen2020-05-06
published2020-05-05
reporterPedro Ribeiro
sourcehttps://packetstormsecurity.com/files/157567/IBM-Data-Risk-Manager-2.0.3-Remote-Code-Execution.html
titleIBM Data Risk Manager 2.0.3 Remote Code Execution