Vulnerability record · CVE-2020-4429 · published 7 May 2020
CVE-2020-4429: IBM Data Risk Manager default admin password enables remote root code execution
Ibm · Data Risk Manager
IBM Data Risk Manager versions 2.0.1 through 2.0.6 ship with a default password for an IDRM administrative account. Because the credential is hard-coded and unauthenticated network access is possible, anyone who can reach the login interface can take over the administrative account. The flaw is rated CVSS 3.1 9.8 (critical) and maps to CWE-798 hard-coded credentials.
Description
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote access to a default administrative credential leading to root code execution is a maximum-severity exposure, and EPSS indicates high exploitation likelihood.
What it is
IBM Data Risk Manager versions 2.0.1 through 2.0.6 ship with a default password for an IDRM administrative account. Because the credential is hard-coded and unauthenticated network access is possible, anyone who can reach the login interface can take over the administrative account. The flaw is rated CVSS 3.1 9.8 (critical) and maps to CWE-798 hard-coded credentials.
Impact
An attacker who logs in with the default administrative password can execute arbitrary code on the underlying system with root privileges, giving full control of the host and any data it manages.
Attack surface
Reachable over the network via the IDRM administrative login; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required. The record does not specify the exact port or endpoint.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.71363, 99.4th percentile), indicating elevated likelihood of exploitation. Reference tags include only a VDB entry and a vendor patch advisory, so no public exploit code is confirmed by the record.
What to do
- Apply the IBM vendor patch referenced in the support advisory (node/6206875) as the first action.
- Change the default IDRM administrative password immediately on any instance that cannot yet be patched.
- Restrict network access to the IDRM administrative interface to trusted management networks only.
- Audit IDRM accounts for default or shared credentials and enforce unique strong passwords.
- If IDRM is no longer supported, migrate off the affected versions or isolate the appliance.
Detection
- Monitor IDRM authentication logs for successful logins to administrative accounts from unexpected source IPs or at unusual times.
- Alert on use of the known default administrative credential against the IDRM login endpoint.
- Watch for post-login process creation or command execution on the IDRM host, especially child processes of the application running as root.
- Review network logs for external or untrusted hosts reaching the IDRM management interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/180534 | VDB Entry |
| https://www.ibm.com/support/pages/node/6206875 | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2024/Nov/0 | |
| http://seclists.org/fulldisclosure/2024/Nov/1 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/180534 | VDB Entry |
| https://www.ibm.com/support/pages/node/6206875 | PatchVendor Advisory |
Track CVE-2020-4429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-4429), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.