← Vulnerability feed

Vulnerability record · CVE-2020-4620 · published 22 September 2020

CVE-2020-4620: Ibm data risk manager unrestricted file upload vulnerability

Ibm · Data Risk Manager

IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 184979.

8.8 CVSS 3.1 High EPSS 5.2% · top 7.8% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 9.0
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious file, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 184979.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-4620 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-4427IBM Data Risk Manager SAML authentication bypassIBM Data Risk Manager versions 2.0.1 through 2.0.6 can be configured with SAML authentication, and a specially crafted HTTP request bypasses that aut…KEVEPSS 70%analysed9.1CVE-2020-4428IBM Data Risk Manager OS command injection allows remote code executionIBM Data Risk Manager versions 2.0.1 through 2.0.4 contain an OS command injection flaw (CWE-78) that lets a remote authenticated attacker run arbitr…KEVEPSS 62%analysed4.3CVE-2020-4430IBM Data Risk Manager path traversal allows arbitrary file downloadIBM Data Risk Manager versions 2.0.1 through 2.0.4 are vulnerable to directory traversal (CWE-22). A remote authenticated attacker can send a special…KEVEPSS 69%analysed9.8CVE-2020-4429IBM Data Risk Manager default admin password enables remote root code executionIBM Data Risk Manager versions 2.0.1 through 2.0.6 ship with a default password for an IDRM administrative account. Because the credential is hard-co…EPSS 72%analysed8.8CVE-2020-4621Ibm data risk manager incorrect authorization vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization …EPSS 1.3%8.8CVE-2020-4611Ibm data risk manager vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 1849…EPSS 1.6%8.1CVE-2020-4617Ibm data risk manager cross-site request forgery vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized ac…EPSS 0.55%7.5CVE-2021-38862Ibm data risk manager inadequate encryption strength vulnerabilityIBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2020-4620), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.