HomeSecurityIBM refused to patch 4 zero-day vulnerabilities

IBM refused to patch 4 zero-day vulnerabilities

IBM

Four zero-day vulnerabilities, discovered on GitHub, were published by security researcher Pedro Ribeiro, Director of Research at Agile Information Security, after IBM refused to patch them and admit their existence.

The vulnerabilities were identified in security , which helps an enterprise uncover, analyze, and visualize data-.

Zero-day vulnerabilities

While the researcher was checking IBM Data Risk Manager, he discovered four zero-day, three of which are critical and one of which is high risk.

The vulnerabilities were as follows:

  • Bypass authentication
  • Add commands
  • Insecure default password
  • Arbitrary file download

The first three vulnerabilities, if used in combination by hackers, could allow remote code execution.

“In addition, two Metasploit modules that bypass authentication and exploit remote code execution and arbitrary file download were released to the public,” he added.

IBM stated that “we have evaluated this report and concluded that this is an out-of-scope application of vulnerability , as this product is intended only for ‘enhanced’ support that our customers pay for.”

The company said that "a error led to an inappropriate response to the researcher who reported this situation to IBM."

Errors fixed

IBM has already patched two of the vulnerabilities and continues to investigate additional actions for further fixes.

The command injection vulnerability in versions 2.0.1, 2.0.2, and 2.0.3 is addressed in version 2.0.4

Arbitrary file download vulnerability detected in versions 2.0.2 and 2.0.3 is addressed in version 2.0.4

To mitigate the vulnerabilities, IBM recommends that users upgrade to IDRM version 2.0.6.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS