Data Risk Manager

Vendor:

First CVE: May 7, 2020 · Active for 6 years

18
Total CVEs
More Total CVEs than 93% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
16.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Data Risk Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2020
6 years ago
Most Recent CVE
Oct 12, 2021
1,747 days ago

CVE Severity & Scoring

Data Risk Manager18 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (88.9%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low8 (44.4%)
High2 (11.1%)
None8 (44.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sendin
May 7, 20209.896YESYES
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
May 7, 20209.191YESYES
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted U
May 7, 20204.384YESNO
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerabilit
May 7, 20209.883NOYES
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.
Oct 12, 20217.524NONO
IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a special
Sep 22, 20208.824NONO
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
Oct 12, 20216.522NONO
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization checks. IBM X-Force ID: 184981.
Sep 22, 20208.822NONO
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to bypass security and execute actions reserved for admins. IBM X-Force ID: 184922.
Sep 22, 20208.822NONO
IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user t
Sep 22, 20208.120NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
3 CVEs
16.7% of CVEs· 98th percentile
Metasploit
3 CVEs
16.7% of CVEs· 97th percentile
Nuclei
2 CVEs
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Data Risk Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.637.924.2%01
2.0.519.871.4%01
2.0.419.871.4%01
2.0.319.871.4%01
2.0.219.871.4%01
2.0.119.871.4%01