Vulnerability record · CVE-2020-4430 · published 7 May 2020
CVE-2020-4430: IBM Data Risk Manager path traversal allows arbitrary file download
Ibm · Data Risk Manager
IBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a specially crafted URL request to download arbitrary files from the system. The flaw matters because it exposes files outside the intended download directory, and CISA added it to the Known Exploited Vulnerabilities catalog.
Description
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityCISA KEV confirms exploitation in the wild and EPSS is very high, though the CVSS impact is limited to low confidentiality loss and requires authentication.
What it is
IBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a specially crafted URL request to download arbitrary files from the system. The flaw matters because it exposes files outside the intended download directory, and CISA added it to the Known Exploited Vulnerabilities catalog.
Impact
An attacker with valid credentials gains read access to arbitrary files on the host, which can expose configuration, credentials or other sensitive data. The CVSS vector limits the direct impact to low confidentiality loss with no integrity or availability effect.
Attack surface
Reachable over the network via a crafted URL request to the web interface; the CVSS vector requires low privileges (authenticated) and no user interaction. No public proof-of-concept detail is given in the record beyond the crafted URL.
Exploitation
CISA KEV lists this as exploited, with a due date of 2022-05-03, and EPSS is very high at 0.685 (99.3rd percentile). No ransomware campaign use is documented, and the references are vendor advisories, patch pages and mailing list posts rather than exploit code.
What to do
- Apply the vendor patch referenced in IBM support node 6206875 for the affected 2.0.1-2.0.4 releases.
- If patching is delayed, restrict network access to the Data Risk Manager interface to trusted management networks.
- Review and reduce accounts with access to the application, since exploitation requires authentication.
- Monitor for and block traversal sequences in URL requests to the application.
- Confirm remediation against CISA KEV required action guidance.
Detection
- Inspect web and proxy logs for URL requests containing traversal sequences such as ../ or encoded variants targeting the Data Risk Manager download endpoint.
- Alert on file download requests returning files outside expected application directories or unusual file types.
- Correlate authenticated sessions with anomalous download volume or access to configuration and credential files.
- Review authentication logs for use of low-privilege accounts performing file download actions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-4430 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "IBM Data Risk Manager Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/180535 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/6206875 | PatchVendor Advisory |
| http://seclists.org/fulldisclosure/2024/Nov/0 | Mailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2024/Nov/1 | Mailing ListThird Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/180535 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/6206875 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-4430 | US Government Resource |
Track CVE-2020-4430 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-4430), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.