Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
High
CVE-2020-4429
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.
0
Attacker Value
Unknown
CVE-2021-38915
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.
0
Attacker Value
Unknown
CVE-2021-38862
Disclosure Date: October 11, 2021 (last updated November 28, 2024)
IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.
0