Skip to content
COOEY

EXPOSURES › CVE-2020-4427

CVE-2020-4427

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-4427 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

A remote attacker could bypass SAML authentication in IBM Data Risk Manager to gain full administrative access.

IBM Data Risk Manager contains a security bypass vulnerability allowing remote attackers to bypass SAML authentication and gain full administrative access via a specially crafted HTTP request. DIB organizations must ensure this CVE is patched and monitored, as it directly undermines access controls and could lead to unauthorized system manipulation or data exfiltration. The vulnerability is actively exploited in the wild, indicating an urgent need for remediation and enhanced monitoring.

Shame score — A remote authentication bypass granting full administrative access is a severe, avoidable failure that directly compromises system integrity and access controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
IBM Data Risk Manager vulnerability allows remote attackers to bypass SAML authentication and gain full administrative access via specially crafted HTTP requests, representing a critical security fail
cooey ↗ severe-fallout -0.80
Critical vulnerability allows remote attackers to bypass SAML authentication and gain full administrative access.
"IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system."
AFFECTED FEDRAMP PRODUCTS · 5
PRODUCTSTATUS
IBM Cloud for Government
IBM
Authorized
IBM Federal HR Cloud
IBM
Authorized
IBM Maximo and TRIRIGA on Cloud for U.S. Federal
IBM
Authorized
MaaS360 Enterprise Mobility Management
IBM
Authorized
SmartCloud for Government
IBM
Authorized