S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Oct 12, 2025

CVE-2020-4427 Scanner

CVE-2020-4427 Scanner - Unauthorized Admin Access vulnerability in IBM Data Risk Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-4427
9.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Data Risk Managerby IBM
2.0.1
Updated Aug 19, 2026View on NVD →
Detail

IBM Data Risk Manager is a comprehensive solution designed for data risk assessment, focusing on identifying, analysing, and mitigating risks associated with data within an organization. It is deployed by enterprises for ensuring data protection compliance and securing sensitive data from unauthorized access or exposure. This software is typically used by IT security teams and data custodians to monitor and manage risks across various data stores. Its integration capabilities with different databases and cloud services make it a popular choice for robust data discovery and classification tasks.

The unauthorized admin access vulnerability targetted by this scanner is significant because it allows attackers to bypass authentication mechanisms and potentially gain administrative privileges. This vulnerability arises specifically from the improper configuration of SAML authentication, enabling attackers to exploit weaknesses in the SAML idpSelection endpoint. Such vulnerabilities can be critical as they could permit unauthorized users access to sensitive data and systems at an administrative level, thereby bypassing traditional security protocols.

Technical details of this vulnerability revolve around the SAML idpSelection endpoint. Attackers can manipulate the SAML authentication flow by sending specially crafted HTTP requests to this endpoint. This could lead to the bypassing of security checks intended to verify user credentials, allowing the execution of privileged actions by unauthorized entities. The endpoint's flawed handling of identifiers and authentication tokens is a critical point of failure, thus necessitating close scrutiny and remediation.

If exploited, attackers could gain full administrative access to IBM Data Risk Manager systems, leading to the exposure of sensitive enterprise data. It may enable data tampering, unauthorized data deletion, or other malicious activities that could severely compromise data integrity, accountability, and confidentiality within the organization. Such disruptions could result in financial losses, reputational damage, and legal implications due to non-compliance with data protection regulations.

REFERENCES

Solution Advice
  • Ensure proper implementation and configuration of SAML authentication mechanisms to prevent bypass vulnerabilities.
  • Update IBM Data Risk Manager to the latest version to mitigate known security vulnerabilities.
  • Regularly audit the authentication processes of your systems, especially those involving third-party integrations like SAML.
  • Increase logging and monitoring of authentication attempts to quickly identify potential unauthorized access incidents.
  • Deploy additional security measures such as two-factor authentication to add an extra layer of protection against unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.