CVE-2020-4429: Critical severity ibm data risk manager vulnerability
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.
Other sources
IBM Data Risk Manager contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of IBM Data Risk Manager?
The vulnerability ID of IBM Data Risk Manager is CVE-2020-4429.
What is the severity level of CVE-2020-4429?
The severity level of CVE-2020-4429 is critical.
How does CVE-2020-4429 impact IBM Data Risk Manager?
CVE-2020-4429 allows a remote attacker to login and execute arbitrary code on the system with root privileges in IBM Data Risk Manager.
Which versions of IBM Data Risk Manager are affected by CVE-2020-4429?
Versions 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 of IBM Data Risk Manager are affected by CVE-2020-4429.
How can I mitigate the vulnerability CVE-2020-4429 in IBM Data Risk Manager?
To mitigate the vulnerability CVE-2020-4429 in IBM Data Risk Manager, update to a patched version that does not have the default password for the IDRM administrative account.