Vulnerability record · CVE-2020-4427 · published 7 May 2020
CVE-2020-4427: IBM Data Risk Manager SAML authentication bypass
Ibm · Data Risk Manager
IBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that authentication. A successful bypass grants full administrative access to the system, making this a complete compromise of the application.
Description
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass yielding full administrative access, with CVSS 9.8, KEV listing and very high EPSS.
What it is
IBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that authentication. A successful bypass grants full administrative access to the system, making this a complete compromise of the application.
Impact
An unauthenticated remote attacker gains full administrative access to the IBM Data Risk Manager instance, allowing control over the application and any data it manages.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw only applies when the product is configured to use SAML authentication.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS probability is 0.70031 (99.3rd percentile), indicating high likelihood of exploitation. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor patch referenced in IBM support node 6206875 for the affected 2.0.x versions.
- If patching cannot be done immediately, restrict network access to the Data Risk Manager interface to trusted management networks only.
- Review SAML authentication configuration and validate that authentication cannot be bypassed by crafted requests.
- Monitor for and investigate any unexpected administrative account activity or configuration changes.
- Track CISA KEV remediation deadlines and confirm the instance is no longer exposed.
Detection
- Inspect web and reverse proxy logs for crafted HTTP requests to authentication or SAML endpoints that return administrative sessions without a valid login.
- Alert on new or unexpected administrative sessions and privilege changes in IBM Data Risk Manager audit logs.
- Correlate authentication events where a session is established without a preceding successful SAML assertion.
- Hunt for access to administrative functions from IPs that have not previously authenticated.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-4427 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "IBM Data Risk Manager Security Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/180532 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/6206875 | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2024/Nov/0 | Mailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2024/Nov/1 | Mailing ListThird Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/180532 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/6206875 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-4427 | US Government Resource |
Track CVE-2020-4427 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-4427), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.