VendorsIBMdatapower_gatewayall versions
Vulnerabilities

IBM Datapower Gateway

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2022-22326
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
Published 2022-07-31 · Modified
4.0EPSS 0.002
CVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.
Published 2015-11-08 · Modified
2.6EPSS 0.010
← Prev2 / 2