EXPOSURES › CVE-2020-4430
CVE-2020-4430
HIGH ⌖ ON CISA KEV · EXPLOITEDIBM Data Risk Manager suffered a directory traversal vulnerability allowing authenticated attackers to download arbitrary files.
An authenticated remote attacker could exploit a directory traversal flaw in IBM Data Risk Manager to download arbitrary files from the system. This exposes sensitive data and violates compliance requirements for protecting information in transit and at rest. DIB organizations must ensure all software is patched and monitored for known vulnerabilities to prevent data exfiltration.
Shame score — A known directory traversal vulnerability was exploited in the wild, allowing data exfiltration from systems running the software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
"IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system."
"CVE 2020-4430 is listed in the database of publicly disclosed computer security flaws."
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
"CVEs and Security Vulnerabilities - OpenCVE"
"Data Breach Directory & Database: Browse 760+ Known Breaches"
"This document lists security updates for Apple software."
| PRODUCT | STATUS |
|---|---|
| IBM Cloud for Government IBM |
Authorized |
| IBM Federal HR Cloud IBM |
Authorized |
| IBM Maximo and TRIRIGA on Cloud for U.S. Federal IBM |
Authorized |
| MaaS360 Enterprise Mobility Management IBM |
Authorized |
| SmartCloud for Government IBM |
Authorized |