CVE-2017-1591
- EPSS 0.96%
- Veröffentlicht 28.09.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...
- EPSS 1.2%
- Veröffentlicht 14.11.2015 03:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it ...
CVE-2015-7412
- EPSS 1.01%
- Veröffentlicht 08.11.2015 22:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to o...