IBM Data Risk Manager是美国IBM公司的一款数据风险管理器。该产品支持发现、分析和可视化业务风险数据等。 IBM Data Risk Manager中存在信任管理问题漏洞,该漏洞源于IDRM管理账户使用了默认密码。攻击者可利用该漏洞登录到系统,获取root权限并执行任意代码。以下产品及版本受到影响:IBM Data Risk Manager 2.0.1版本,2.0.2版本,2.0.3版本,2.0.4版本,2.0.5版本,2.0.6版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Data Risk Manager | 2.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID- 180534. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2020/CVE-2020-4429.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-4430 | IBM Data Risk Manager 路径遍历漏洞 | |
| CVE-2020-4427 | IBM Data Risk Manager 授权问题漏洞 | |
| CVE-2020-4428 | IBM Data Risk Manager 操作系统命令注入漏洞 |
No comments yet