Known Vulnerabilities for Data Risk Manager by Ibm
Listed below are 10 of the newest known vulnerabilities associated with "Data Risk Manager" by "Ibm".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-38915 json | IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-For... | 6.5 - MEDIUM | 2021-10-12 | 2021-10-18 |
| CVE-2021-38862 json | IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt... | 7.5 - HIGH | 2021-10-12 | 2021-10-18 |
| CVE-2020-4622 json | IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses fo... | 7.5 - HIGH | 2020-09-22 | 2020-09-22 |
| CVE-2020-4621 json | IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to ins... | 8.8 - HIGH | 2020-09-22 | 2020-09-22 |
| CVE-2020-4620 json | IBM Data Risk Manager (iDNA) 2.0.6 could allow a remote authenticated attacker to upload arbitrary files, caused by the impro... | 8.8 - HIGH | 2020-09-22 | 2020-09-22 |
| CVE-2020-4619 json | IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user.... | 6.5 - MEDIUM | 2020-09-22 | 2020-09-22 |
| CVE-2020-4618 json | IBM Data Risk Manager (iDNA) 2.0.6 could allow a privileged user to cause a denial of service due to improper input validatio... | 4.9 - MEDIUM | 2020-09-22 | 2020-09-22 |
| CVE-2020-4617 json | IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malic... | 8.1 - HIGH | 2020-09-22 | 2020-09-22 |
| CVE-2020-4616 json | IBM Data Risk Manager (iDNA) 2.0.6 could disclose sensitive username information to an attacker using a specially crafted HTT... | 5.3 - MEDIUM | 2020-09-22 | 2021-07-21 |
| CVE-2020-4615 json | IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... | 5.4 - MEDIUM | 2020-09-22 | 2020-09-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Data Risk Manager | 2.0.6.4 | |||
| Application | Ibm | Data Risk Manager | 2.0.6 | |||
| Application | Ibm | Data Risk Manager | 2.0.5 | |||
| Application | Ibm | Data Risk Manager | 2.0.4 | |||
| Application | Ibm | Data Risk Manager | 2.0.3 | |||
| Application | Ibm | Data Risk Manager | 2.0.2 | |||
| Application | Ibm | Data Risk Manager | 2.0.1 |