PT-2020-18167 · Ibm · Ibm Data Risk Manager

Published

2020-09-22

·

Updated

2020-09-22

·

CVE-2020-4620

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Data Risk Manager (iDNA) version 2.0.6
Description The issue is caused by the improper validation of file extensions, allowing a remote authenticated attacker to upload arbitrary files. By sending a specially-crafted HTTP request, a remote attacker could exploit this to upload a malicious file, potentially executing arbitrary code on the vulnerable system.
Recommendations For IBM Data Risk Manager (iDNA) version 2.0.6, consider restricting file uploads or validating file extensions to prevent malicious file uploads until a patch is available. As a temporary workaround, restrict access to the file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4620

Affected Products

Ibm Data Risk Manager