CVE-2020-4429
87Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 10epss 71%
from disclosure to weapon0 days
Published on NVDMay 7
metasploitApr 21
VulnCheck+1923d
exploitation probability
71%top 1% of all CVEs
observed exploitation
yesVulnCheck
In short
IBM Data Risk Manager comes with a built-in default password for an administrative account that is never changed. An attacker can use this password to log in remotely and gain complete control of the system, including the ability to run malicious code with the highest privileges.
Technical detail
A hardcoded default credential exists for an IDRM administrative account across versions 2.0.1–2.0.6, allowing remote unauthenticated access. An attacker can authenticate and achieve arbitrary code execution with root privileges, leading to complete system compromise.
Summary generated and translated by AI from the official description.
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.
CVSS:3.0/S:C/AV:N/A:H/AC:L/PR:N/C:H/I:H/UI:N/RC:C/RL:O/E:U
Affected products
IBM · Data Risk Manager