EXPOSURES › CVE-2020-4428
CVE-2020-4428
HIGH ⌖ ON CISA KEV · EXPLOITEDIBM Data Risk Manager had a remote code execution vulnerability allowing authenticated attackers to execute commands on the system.
IBM Data Risk Manager contained an unspecified vulnerability enabling remote, authenticated attackers to execute arbitrary commands on the system. This is a critical failure for DIB organizations because it directly violates CMMC/NIST 800-171 requirements for preventing unauthorized access and protecting controlled unclassified information (CUI). Organizations must ensure all software, especially data management tools, are patched against known vulnerabilities and monitored for exploitation in the wild.
Shame score — The vulnerability was actively exploited in the wild (KEV status) and allowed remote code execution, indicating a significant gap in IBM's patch management and vulnerability disclosure processes.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
"IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system."
| PRODUCT | STATUS |
|---|---|
| IBM Cloud for Government IBM |
Authorized |
| IBM Federal HR Cloud IBM |
Authorized |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal IBM |
Authorized |
| MaaS360 Enterprise Mobility Management IBM |
Authorized |
| SmartCloud for Government IBM |
Authorized |