CVE-2018-1663
- EPSS 0.27%
- Veröffentlicht 07.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:09
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain s...
CVE-2018-1669
- EPSS 0.4%
- Veröffentlicht 25.09.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:00:10
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (X...
CVE-2018-1664
- EPSS 0.04%
- Veröffentlicht 25.09.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:00:09
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization he...
CVE-2018-1421
- EPSS 0.32%
- Veröffentlicht 04.04.2018 18:29:02
- Zuletzt bearbeitet 21.11.2024 03:59:47
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cons...
CVE-2017-1773
- EPSS 0.11%
- Veröffentlicht 31.01.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:22:20
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
CVE-2017-1591
- EPSS 0.28%
- Veröffentlicht 28.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...
- EPSS 0.23%
- Veröffentlicht 14.11.2015 03:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it ...
CVE-2015-7412
- EPSS 0.21%
- Veröffentlicht 08.11.2015 22:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to o...