A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2020-4427

IBM Data Risk Manager Security Bypass Vulnerability

Published
2021-11-03
Modified
2026-07-31
Sources
cisa-kev

Summary

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.