VendorsIBMapplication_gatewayall versions
Vulnerabilities

IBM Application Gateway

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-28787
IBM Security Verify Access information disclosure
Published 2024-04-04 · Analyzed
10.0EPSS 0.008
CVE-2021-20576
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
Published 2021-05-31 · Modified
7.5EPSS 0.025
CVE-2024-45655
IBM Application Gateway incorrect permission assignment
Published 2025-06-03 · Analyzed
5.5EPSS 0.001
CVE-2022-22387
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965.
Published 2022-09-28 · Modified
5.4EPSS 0.005
CVE-2025-36397
Security vulnerabilities have been found in IBM Application Gateway
Published 2026-01-20 · Analyzed
5.4EPSS 0.002
CVE-2025-36396
Security vulnerabilities have been found in IBM Application Gateway
Published 2026-01-20 · Analyzed
5.4EPSS 0.002
CVE-2021-20575
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.
Published 2021-05-31 · Modified
4.0EPSS 0.003