← Vulnerability feed

Vulnerability record · CVE-2020-4428 · published 7 May 2020

CVE-2020-4428: IBM Data Risk Manager OS command injection allows remote code execution

Ibm · Data Risk Manager

IBM Data Risk Manager versions 2.0.1 through 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote authenticated attacker run arbitrary commands on the host. Because the commands execute with the application's privileges and the CVSS scope is changed, a compromise can extend beyond the vulnerable component. It is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed target in the wild.

9.1 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 62% · top 0.9% CWE-78 · OS command injection
9.1CVSS 3.1 base score, v2 9.0
62%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.1, confirmed KEV exploitation, and very high EPSS make this an urgent patch-first item despite the authentication requirement.

What it is

IBM Data Risk Manager versions 2.0.1 through 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote authenticated attacker run arbitrary commands on the host. Because the commands execute with the application's privileges and the CVSS scope is changed, a compromise can extend beyond the vulnerable component. It is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed target in the wild.

Impact

An attacker with valid credentials gains arbitrary command execution on the Data Risk Manager server, which can lead to full host compromise and lateral movement into connected systems. The changed-scope rating means impact is not confined to the application itself.

Attack surface

Reachable over the network (AV:N) with no user interaction (UI:N), but it requires authenticated access with high privileges (PR:H). The flaw is in the product's command handling, so any exposed Data Risk Manager interface is a candidate entry point.

Exploitation

CISA added it to the KEV catalog on 2021-11-03 with a remediation due date of 2022-05-03, indicating known exploitation; EPSS is very high at roughly 0.617 (99th percentile). No ransomware campaign use is recorded, and no public exploit reference is tagged in the supplied data.

What to do

  • Apply the vendor patch from IBM support document 6206875; this is the primary fix.
  • If patching is not immediately possible, restrict network access to Data Risk Manager to trusted management networks only.
  • Enforce least privilege and review accounts with high privileges on the product, since exploitation requires authenticated high-privilege access.
  • Monitor IBM advisories and the KEV entry for updated guidance and confirm the installed version is 2.0.4 or later as patched.

Detection

  • Alert on unexpected child processes spawned by the Data Risk Manager application or its web server user.
  • Monitor application and system logs for command-injection patterns such as shell metacharacters in request parameters.
  • Baseline normal outbound connections from the Data Risk Manager host and alert on new or unusual destinations.
  • Audit authentication logs for high-privilege account activity preceding process creation events on the server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-4428 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "IBM Data Risk Manager Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4428 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4427IBM Data Risk Manager SAML authentication bypassIBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that aut…KEVEPSS 70%analysed4.3CVE-2020-4430IBM Data Risk Manager path traversal allows arbitrary file downloadIBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a special…KEVEPSS 69%analysed9.8CVE-2020-4429IBM Data Risk Manager default admin password enables remote root code executionIBM Data Risk Manager versions 2.0.1 through 2.0.6 ship with a default password for an IDRM administrative account. Because the credential is hard-co…EPSS 72%analysed8.8CVE-2020-4620Ibm data risk manager unrestricted file upload vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…EPSS 5.2%8.8CVE-2020-4621Ibm data risk manager incorrect authorization vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …EPSS 1.3%8.8CVE-2020-4611Ibm data risk manager vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849…EPSS 1.6%8.1CVE-2020-4617Ibm data risk manager cross-site request forgery vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…EPSS 0.55%7.5CVE-2021-38862Ibm data risk manager inadequate encryption strength vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2020-4428), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.