← לוח פגיעויות

CVE-2020-4430

בינונית 4.3 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
IBM Data Risk Manager Directory Traversal Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.

מדדים

CVSS 3.1
4.3 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS — סבירות ניצול
69% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-22

מוצרים מושפעים

ibm: data risk manager

קישורים