CVE-2018-1663
- EPSS 0.27%
- Published 07.12.2018 16:29:00
- Last modified 21.11.2024 04:00:09
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain s...
CVE-2018-1669
- EPSS 0.4%
- Published 25.09.2018 15:29:01
- Last modified 21.11.2024 04:00:10
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (X...
CVE-2018-1664
- EPSS 0.04%
- Published 25.09.2018 15:29:01
- Last modified 21.11.2024 04:00:09
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization he...
CVE-2018-1421
- EPSS 0.32%
- Published 04.04.2018 18:29:02
- Last modified 21.11.2024 03:59:47
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cons...
CVE-2017-1773
- EPSS 0.11%
- Published 31.01.2018 15:29:00
- Last modified 21.11.2024 03:22:20
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
CVE-2017-1591
- EPSS 0.28%
- Published 28.09.2017 01:29:02
- Last modified 20.04.2025 01:37:25
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...
- EPSS 0.23%
- Published 14.11.2015 03:59:07
- Last modified 12.04.2025 10:46:40
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it ...
CVE-2015-7412
- EPSS 0.21%
- Published 08.11.2015 22:59:19
- Last modified 12.04.2025 10:46:40
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to o...