Skip to content
COOEY

FAIL › dossier

Data Risk Manager

PRODUCT

· dossier confidence 60%

Advanced Data Risk Management (ADRM) is a data risk management product with a concerning security track record. It has suffered multiple high-severity vulnerabilities including SAML bypass, directory traversal, and remote code execution, with at least one vulnerability remaining actively exploited as of 2024.

PROFILE
CategoryData Risk ManagementWhat they doAdvanced Data Risk Management (ADRM) is a product focused on data risk management and security.
SECURITY POSTURE

The product has a history of high-severity vulnerabilities including SAML authentication bypass, directory traversal, and remote code execution, with at least one CVE (CVE-2023-39410) remaining actively exploited as of 2024.

Notable failures
  • CVE-2020-4427 SAML auth bypass
  • CVE-2020-4430 directory traversal
  • CVE-2020-4428 remote code execution
  • CVE-2023-39410 actively exploited RCE
Patterns: repeated high-severity vulnerabilities in core authentication and execution paths; delayed patching of actively exploited vulnerabilities
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-4427 high A remote attacker could bypass SAML authentication in IBM Data Risk Manager to gain full administrative access.
2021-11-03 CVE-2020-4430 high IBM Data Risk Manager suffered a directory traversal vulnerability allowing authenticated attackers to download arbitrary files.
2021-11-03 CVE-2020-4428 high IBM Data Risk Manager had a remote code execution vulnerability allowing authenticated attackers to execute commands on the system.
Open questions: Exact founding year and headquarters location of the product or vendor · Current ownership structure and vendor identity
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-29 04:11:57.097082+00:00