← Vulnerability feed

Vulnerability record · CVE-2020-4427 · published 7 May 2020

CVE-2020-4427: IBM Data Risk Manager SAML authentication bypass

Ibm · Data Risk Manager

IBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that authentication. A successful bypass grants full administrative access to the system, making this a complete compromise of the application.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 70% · top 0.6% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 9.0
70%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable authentication bypass yielding full administrative access, with CVSS 9.8, KEV listing and very high EPSS.

What it is

IBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that authentication. A successful bypass grants full administrative access to the system, making this a complete compromise of the application.

Impact

An unauthenticated remote attacker gains full administrative access to the IBM Data Risk Manager instance, allowing control over the application and any data it manages.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw only applies when the product is configured to use SAML authentication.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS probability is 0.70031 (99.3rd percentile), indicating high likelihood of exploitation. No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor patch referenced in IBM support node 6206875 for the affected 2.0.x versions.
  • If patching cannot be done immediately, restrict network access to the Data Risk Manager interface to trusted management networks only.
  • Review SAML authentication configuration and validate that authentication cannot be bypassed by crafted requests.
  • Monitor for and investigate any unexpected administrative account activity or configuration changes.
  • Track CISA KEV remediation deadlines and confirm the instance is no longer exposed.

Detection

  • Inspect web and reverse proxy logs for crafted HTTP requests to authentication or SAML endpoints that return administrative sessions without a valid login.
  • Alert on new or unexpected administrative sessions and privilege changes in IBM Data Risk Manager audit logs.
  • Correlate authentication events where a session is established without a preceding successful SAML assertion.
  • Hunt for access to administrative functions from IPs that have not previously authenticated.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-4427 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "IBM Data Risk Manager Security Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4427 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-4428IBM Data Risk Manager OS command injection allows remote code executionIBM Data Risk Manager versions 2.0.1 through 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote authenticated attacker run arbitr…KEVEPSS 62%analysed4.3CVE-2020-4430IBM Data Risk Manager path traversal allows arbitrary file downloadIBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a special…KEVEPSS 69%analysed9.8CVE-2020-4429IBM Data Risk Manager default admin password enables remote root code executionIBM Data Risk Manager versions 2.0.1 through 2.0.6 ship with a default password for an IDRM administrative account. Because the credential is hard-co…EPSS 72%analysed8.8CVE-2020-4620Ibm data risk manager unrestricted file upload vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…EPSS 5.2%8.8CVE-2020-4621Ibm data risk manager incorrect authorization vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …EPSS 1.3%8.8CVE-2020-4611Ibm data risk manager vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849…EPSS 1.6%8.1CVE-2020-4617Ibm data risk manager cross-site request forgery vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…EPSS 0.55%7.5CVE-2021-38862Ibm data risk manager inadequate encryption strength vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2020-4427), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.