← Vulnerability feed

Vulnerability record · CVE-2020-4430 · published 7 May 2020

CVE-2020-4430: IBM Data Risk Manager path traversal allows arbitrary file download

Ibm · Data Risk Manager

IBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a specially crafted URL request to download arbitrary files from the system. The flaw matters because it exposes files outside the intended download directory, and CISA added it to the Known Exploited Vulnerabilities catalog.

4.3 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 EPSS 69% · top 0.7% CWE-22 · Path traversal
4.3CVSS 3.1 base score, v2 4.0
69%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCISA KEV confirms exploitation in the wild and EPSS is very high, though the CVSS impact is limited to low confidentiality loss and requires authentication.

What it is

IBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a specially crafted URL request to download arbitrary files from the system. The flaw matters because it exposes files outside the intended download directory, and CISA added it to the Known Exploited Vulnerabilities catalog.

Impact

An attacker with valid credentials gains read access to arbitrary files on the host, which can expose configuration, credentials or other sensitive data. The CVSS vector limits the direct impact to low confidentiality loss with no integrity or availability effect.

Attack surface

Reachable over the network via a crafted URL request to the web interface; the CVSS vector requires low privileges (authenticated) and no user interaction. No public proof-of-concept detail is given in the record beyond the crafted URL.

Exploitation

CISA KEV lists this as exploited, with a due date of 2022-05-03, and EPSS is very high at 0.685 (99.3rd percentile). No ransomware campaign use is documented, and the references are vendor advisories, patch pages and mailing list posts rather than exploit code.

What to do

  • Apply the vendor patch referenced in IBM support node 6206875 for the affected 2.0.1-2.0.4 releases.
  • If patching is delayed, restrict network access to the Data Risk Manager interface to trusted management networks.
  • Review and reduce accounts with access to the application, since exploitation requires authentication.
  • Monitor for and block traversal sequences in URL requests to the application.
  • Confirm remediation against CISA KEV required action guidance.

Detection

  • Inspect web and proxy logs for URL requests containing traversal sequences such as ../ or encoded variants targeting the Data Risk Manager download endpoint.
  • Alert on file download requests returning files outside expected application directories or unusual file types.
  • Correlate authenticated sessions with anomalous download volume or access to configuration and credential files.
  • Review authentication logs for use of low-privilege accounts performing file download actions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-4430 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "IBM Data Risk Manager Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4430 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4427IBM Data Risk Manager SAML authentication bypassIBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that aut…KEVEPSS 70%analysed9.1CVE-2020-4428IBM Data Risk Manager OS command injection allows remote code executionIBM Data Risk Manager versions 2.0.1 through 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote authenticated attacker run arbitr…KEVEPSS 62%analysed9.8CVE-2020-4429IBM Data Risk Manager default admin password enables remote root code executionIBM Data Risk Manager versions 2.0.1 through 2.0.6 ship with a default password for an IDRM administrative account. Because the credential is hard-co…EPSS 72%analysed8.8CVE-2020-4620Ibm data risk manager unrestricted file upload vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file e…EPSS 5.2%8.8CVE-2020-4621Ibm data risk manager incorrect authorization vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …EPSS 1.3%8.8CVE-2020-4611Ibm data risk manager vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849…EPSS 1.6%8.1CVE-2020-4617Ibm data risk manager cross-site request forgery vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…EPSS 0.55%7.5CVE-2021-38862Ibm data risk manager inadequate encryption strength vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2020-4430), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.