CVE-2020-4427: IBM Data Risk Manager Security Bypass Vulnerability
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
Other sources
IBM Data Risk Manager could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If upgrading is not immediately possible, reconfigure IBM Data Risk Manager to not use SAML authentication to prevent the security bypass.
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-4427.
What is the severity level of CVE-2020-4427?
The severity level of CVE-2020-4427 is critical.
Which version of IBM Data Risk Manager is affected by CVE-2020-4427?
IBM Data Risk Manager versions 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 are affected by CVE-2020-4427.
How can an attacker exploit CVE-2020-4427?
An attacker can exploit CVE-2020-4427 by sending a specially crafted HTTP request to bypass security restrictions when IBM Data Risk Manager is configured with SAML authentication.
How can I fix CVE-2020-4427?
To fix CVE-2020-4427, it is recommended to upgrade IBM Data Risk Manager to a version that is not affected by the vulnerability.