First published: Mon Sep 21 2020(Updated: )
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 184983.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Risk Manager | <=2.0.6 | |
IBM Data Risk Manager | <2.0.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4622 is high with a score of 7.5.
CVE-2020-4622 affects IBM Data Risk Manager version 2.0.6.
Yes, patches are available for CVE-2020-4622. You can find the patch at: [IBM Data Risk Manager Patch](https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Data+Risk+Manager&release=2.0.4.1&platform=Linux&function=all)
The Common Weakness Enumeration (CWE) ID for CVE-2020-4622 is 798.
You can find more information about CVE-2020-4622 at: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/184983) and [IBM Support Pages](https://www.ibm.com/support/pages/node/6335281)