cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2022-40228,https://securityvulnerability.io/vulnerability/CVE-2022-40228,IBM DataPower Gateway session fixation," IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235527. ",IBM,Datapower Gateway,3.7,LOW,0.0005000000237487257,false,,false,false,false,,,false,false,,2022-11-22T18:52:13.196Z,0 CVE-2022-31773,https://securityvulnerability.io/vulnerability/CVE-2022-31773,Cross-Site Request Forgery Vulnerability in IBM DataPower Gateway,"IBM DataPower Gateway versions V10CD, 10.0.1, and 2018.4.1 are prone to a Cross-Site Request Forgery (CSRF) flaw that may allow attackers to execute unauthorized actions on behalf of trusted users. This exploit occurs when the application fails to adequately validate requests from authenticated users, leading to potential unauthorized changes and data manipulation. For more information and mitigation strategies, visit [IBM Support](https://www.ibm.com/support/pages/node/6615307) or [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/228357).",IBM,Datapower Gateway,8.8,HIGH,0.0007300000288523734,false,,false,false,false,,,false,false,,2022-08-26T18:15:00.000Z,0 CVE-2022-31776,https://securityvulnerability.io/vulnerability/CVE-2022-31776,Server-Side Request Forgery in IBM DataPower Gateway,"IBM DataPower Gateway versions from 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 are susceptible to a server-side request forgery (SSRF) vulnerability. An authenticated attacker could exploit this weakness to send unauthorized requests from the gateway, which may lead to network enumeration and could be leveraged to carry out additional malicious actions. For more details, please refer to IBM's official support page or the IBM X-Force Exchange.",IBM,Datapower Gateway,6.5,MEDIUM,0.0009200000204145908,false,,false,false,false,,,false,false,,2022-08-01T11:15:00.000Z,0 CVE-2022-32750,https://securityvulnerability.io/vulnerability/CVE-2022-32750,Cross-Site Scripting Vulnerability in IBM DataPower Gateway,"IBM DataPower Gateway versions 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 are susceptible to cross-site scripting attacks. This vulnerability enables an attacker to inject arbitrary JavaScript code into the Web UI, potentially compromising the functionality of the application. The exploitation of this flaw could result in the unauthorized disclosure of user credentials within a trusted session, posing significant risks to user data and application integrity. For further details, see the IBM support document and IBM X-Force ID: 228435.",IBM,Datapower Gateway,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2022-08-01T11:15:00.000Z,0 CVE-2022-31775,https://securityvulnerability.io/vulnerability/CVE-2022-31775,XML External Entity Injection in IBM DataPower Gateway,"IBM DataPower Gateway, specifically versions 10.0.2.0 through 10.0.4.0, and 2018.4.1.0 through 2018.4.1.21, is susceptible to an XML External Entity Injection vulnerability when handling XML data. This allows remote attackers to exploit the vulnerability, potentially leading to the exposure of sensitive information or excessive memory consumption. For detailed guidance on mitigation, refer to IBM's support documentation.",IBM,Datapower Gateway,5.5,MEDIUM,0.001449999981559813,false,,false,false,false,,,false,false,,2022-08-01T11:15:00.000Z,0 CVE-2022-31774,https://securityvulnerability.io/vulnerability/CVE-2022-31774,Cross-Site Scripting Vulnerability in IBM DataPower Gateway,The vulnerability in IBM DataPower Gateway allows attackers to inject arbitrary JavaScript code through the web user interface. This could lead to unauthorized access and the potential for credentials to be exposed within a trusted session. Proper input validation and output encoding may be necessary to mitigate the risks associated with this vulnerability.,IBM,Datapower Gateway,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2022-08-01T11:15:00.000Z,0 CVE-2022-22326,https://securityvulnerability.io/vulnerability/CVE-2022-22326,Unauthorized Access Vulnerability in IBM Datapower Gateway,"The vulnerability in IBM Datapower Gateway allows attackers to potentially view restricted logs and files due to insufficient authorization checks. This weakness affects various versions of the product, potentially exposing sensitive information if exploited. Proper authorization mechanisms should be implemented to mitigate the risk associated with this vulnerability.",IBM,Datapower Gateway,4,MEDIUM,0.00046999999904073775,false,,false,false,false,,,false,false,,2022-07-29T00:00:00.000Z,0 CVE-2021-38944,https://securityvulnerability.io/vulnerability/CVE-2021-38944,HTTP Header Injection Vulnerability in IBM DataPower Gateway,"IBM DataPower Gateway is vulnerable to an HTTP header injection issue due to improper input validation of HOST headers. This vulnerability can be exploited by attackers to launch various attacks such as cross-site scripting and session hijacking, compromising the security of the affected system. Organizations using IBM DataPower Gateway versions 10.0.2.0 through 1.0.3.0 and 2018.4.1.0 through 2018.4.1.18 should take necessary actions to mitigate potential risks.",IBM,Datapower Gateway,4.8,MEDIUM,0.000699999975040555,false,,false,false,false,,,false,false,,2022-05-18T20:15:00.000Z,0 CVE-2021-38872,https://securityvulnerability.io/vulnerability/CVE-2021-38872,Denial of Service Vulnerability in IBM DataPower Gateway,"IBM DataPower Gateway versions 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 are vulnerable to a denial of service attack. An attacker could exploit this vulnerability by sending a high volume of requests, consuming server resources and rendering the gateway unavailable to legitimate users. Organizations using the affected versions should implement patching and monitoring strategies to mitigate potential disruptions.",IBM,Datapower Gateway,5.3,MEDIUM,0.0012799999676644802,false,,false,false,false,,,false,false,,2022-05-17T17:15:00.000Z,0 CVE-2020-4994,https://securityvulnerability.io/vulnerability/CVE-2020-4994,Denial of Service Vulnerability in IBM DataPower Gateway,"The IBM DataPower Gateway versions 10.0.1.0 to 10.0.1.4 and 2018.4.1.0 to 2018.4.1.17 are subject to a vulnerability that allows remote users to execute a temporary denial of service. This can be achieved by sending specially crafted invalid HTTP requests, potentially disrupting service availability. Organizations using these versions should assess their exposure and apply mitigations as necessary to ensure continued service availability.",IBM,Datapower Gateway,5.3,MEDIUM,0.0012799999676644802,false,,false,false,false,,,false,false,,2022-05-17T17:15:00.000Z,0 CVE-2021-38910,https://securityvulnerability.io/vulnerability/CVE-2021-38910,Remote Security Bypass in IBM DataPower Gateway,"The IBM DataPower Gateway versions V10CD, 10.0.1, and 2108.4.1 are susceptible to a security vulnerability that allows remote attackers to bypass existing security measures. This issue arises from improper validation of input data, which could be exploited by sending specially crafted JSON messages. Successful exploitation may allow attackers to alter data structures and fields, leading to unauthorized changes and access.",IBM,Datapower Gateway,3.7,LOW,0.000910000002477318,false,,false,false,false,,,false,false,,2022-03-10T20:15:00.000Z,0 CVE-2020-4992,https://securityvulnerability.io/vulnerability/CVE-2020-4992,Cross-Site Request Forgery Vulnerability in IBM DataPower Gateway,"The IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.16 are susceptible to cross-site request forgery (CSRF). This vulnerability can allow attackers to execute unauthorized actions by leveraging the trust a victim’s web browser has with the website. Such attacks can potentially compromise sensitive user data and operations. For further details, refer to the IBM X-Force ID: 192737 and check the [IBM support page](https://www.ibm.com/support/pages/node/6481679) and [vulnerability entry](https://exchange.xforce.ibmcloud.com/vulnerabilities/192737) for mitigation and remediation guidance.",IBM,Datapower Gateway,4.3,MEDIUM,0.0008099999977275729,false,,false,false,false,,,false,false,,2021-08-17T14:15:00.000Z,0 CVE-2020-5008,https://securityvulnerability.io/vulnerability/CVE-2020-5008,,"IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 193033.",IBM,Datapower Gateway,3.7,LOW,0.0006399999838322401,false,,false,false,false,,,false,false,,2021-06-07T14:15:00.000Z,0 CVE-2020-4831,https://securityvulnerability.io/vulnerability/CVE-2020-4831,,IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 189965.,IBM,Datapower Gateway,5.9,MEDIUM,0.0010100000072270632,false,,false,false,false,,,false,false,,2021-03-12T17:15:00.000Z,0 CVE-2020-5014,https://securityvulnerability.io/vulnerability/CVE-2020-5014,,IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247.,IBM,Datapower Gateway,6.7,MEDIUM,0.0008500000112690032,false,,false,false,true,2020-10-18T10:32:32.000Z,true,false,false,,2021-03-08T18:15:00.000Z,0 CVE-2020-4528,https://securityvulnerability.io/vulnerability/CVE-2020-4528,,"IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.",IBM,Datapower Gateway,5.9,MEDIUM,0.0004199999966658652,false,,false,false,false,,,false,false,,2020-10-06T16:15:00.000Z,0 CVE-2020-4579,https://securityvulnerability.io/vulnerability/CVE-2020-4579,,IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.,IBM,Datapower Gateway,7.5,HIGH,0.0014100000262260437,false,,false,false,false,,,false,false,,2020-09-21T15:15:00.000Z,0 CVE-2020-4580,https://securityvulnerability.io/vulnerability/CVE-2020-4580,,IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439.,IBM,Datapower Gateway,7.5,HIGH,0.0012799999676644802,false,,false,false,false,,,false,false,,2020-09-21T15:15:00.000Z,0 CVE-2020-4581,https://securityvulnerability.io/vulnerability/CVE-2020-4581,,IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441.,IBM,Datapower Gateway,7.5,HIGH,0.0012799999676644802,false,,false,false,false,,,false,false,,2020-09-21T15:15:00.000Z,0 CVE-2020-4203,https://securityvulnerability.io/vulnerability/CVE-2020-4203,,IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956.,IBM,Datapower Gateway,4.9,MEDIUM,0.0007099999929778278,false,,false,false,false,,,false,false,,2020-03-19T14:15:00.000Z,0 CVE-2020-4205,https://securityvulnerability.io/vulnerability/CVE-2020-4205,,"IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.",IBM,Datapower Gateway,5,MEDIUM,0.0007200000109151006,false,,false,false,false,,,false,false,,2020-03-19T14:15:00.000Z,0 CVE-2019-4621,https://securityvulnerability.io/vulnerability/CVE-2019-4621,,IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.,IBM,Datapower Gateway,8.1,HIGH,0.006579999811947346,false,,false,false,false,,,false,false,,2019-12-09T23:15:00.000Z,0 CVE-2019-4294,https://securityvulnerability.io/vulnerability/CVE-2019-4294,,"IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.",IBM,"MQ Appliance,Datapower Gateway",8.4,HIGH,0.0004299999854993075,false,,false,false,false,,,false,false,,2019-08-20T19:15:00.000Z,0 CVE-2018-1666,https://securityvulnerability.io/vulnerability/CVE-2018-1666,,"IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.",IBM,Datapower Gateway,4.3,MEDIUM,0.0004900000058114529,false,,false,false,false,,,false,false,,2019-02-07T15:29:00.000Z,0 CVE-2018-1668,https://securityvulnerability.io/vulnerability/CVE-2018-1668,,"IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows ""null"" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.",IBM,Datapower Gateway,5.3,MEDIUM,0.0012000000569969416,false,,false,false,false,,,false,false,,2019-01-29T16:29:00.000Z,0