CVE-2020-4528
- EPSS 0.29%
- Veröffentlicht 06.10.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:32:51
IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.
CVE-2020-4581
- EPSS 1.6%
- Veröffentlicht 21.09.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:56
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441.
CVE-2020-4579
- EPSS 2.24%
- Veröffentlicht 21.09.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:56
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.
CVE-2020-4580
- EPSS 1.6%
- Veröffentlicht 21.09.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:56
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439.
CVE-2020-4205
- EPSS 0.53%
- Veröffentlicht 19.03.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:23
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.
CVE-2020-4203
- EPSS 1.29%
- Veröffentlicht 19.03.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:23
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956.
CVE-2019-4621
- EPSS 1.64%
- Veröffentlicht 09.12.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:43:53
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. ...
CVE-2019-4294
- EPSS 0.95%
- Veröffentlicht 20.08.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:43:26
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, ca...
CVE-2018-1666
- EPSS 0.84%
- Veröffentlicht 07.02.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:10
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be display...
CVE-2018-1668
- EPSS 1.4%
- Veröffentlicht 29.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:10
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID...