CVE-2020-4203
- EPSS 0.27%
- Published 19.03.2020 14:15:12
- Last modified 21.11.2024 05:32:23
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956.
CVE-2019-4621
- EPSS 0.81%
- Published 09.12.2019 23:15:11
- Last modified 21.11.2024 04:43:53
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. ...
CVE-2019-4294
- EPSS 0.1%
- Published 20.08.2019 19:15:11
- Last modified 21.11.2024 04:43:26
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, ca...
CVE-2018-1666
- EPSS 0.17%
- Published 07.02.2019 15:29:00
- Last modified 21.11.2024 04:00:10
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be display...
CVE-2018-1668
- EPSS 0.15%
- Published 29.01.2019 16:29:00
- Last modified 21.11.2024 04:00:10
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID...
CVE-2018-1677
- EPSS 0.05%
- Published 20.12.2018 14:29:00
- Last modified 21.11.2024 04:00:11
IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of s...
CVE-2018-1661
- EPSS 0.15%
- Published 20.12.2018 14:29:00
- Last modified 21.11.2024 04:00:09
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.
CVE-2018-1667
- EPSS 0.11%
- Published 13.12.2018 16:29:00
- Last modified 21.11.2024 04:00:10
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2018-1665
- EPSS 0.1%
- Published 13.12.2018 16:29:00
- Last modified 21.11.2024 04:00:09
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highl...
CVE-2018-1652
- EPSS 0.05%
- Published 11.12.2018 16:29:00
- Last modified 21.11.2024 04:00:08
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 cou...