Technical Severity
MEDIUM
CVSS v3.1 Metrics
4.3
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.0/S:U/AV:N/A:N/AC:L/C:L/PR:L/UI:N/I:N/E:U/RC:C/RL:O
Exploitation Likelihood
EPSS Prediction
84.29
%
Predictive Probability
Percentile Rank
99.3
th
Documented as more likely to be exploited than 99.3% of known CVEs.
Detection Date
Nov 03, 2021
Remediation Due
May 03, 2022
CISA Catalog Active
Threat Analysis
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.
Remediation Directive
Apply updates per vendor instructions.