Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm datapower gateway vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-38944
IBM DataPower Gateway 10.0.2.0 up to and including 1.0.3.0, 10.0.1.0 up to and including 10.0.1.5, and 2018.4.1.0 up to and including 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an malicious user...
Ibm Datapower Gateway
4.3
CVSSv2
CVE-2020-4992
IBM DataPower Gateway 2018.4.1.0 up to and including 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an malicious user to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.
Ibm Datapower Gateway
4.3
CVSSv2
CVE-2018-1663
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote malicious user to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information usi...
Ibm Datapower Gateway 2018.4
Ibm Datapower Gateway
4.3
CVSSv2
CVE-2017-1773
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
Ibm Datapower Gateway
4.3
CVSSv2
CVE-2017-1591
IBM WebSphere DataPower Appliances 7.0.0 up to and including 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a...
Ibm Datapower Gateway 7.5.1.6
Ibm Datapower Gateway 7.5.1.5
Ibm Datapower Gateway 7.5.1.4
Ibm Datapower Gateway 7.5.1.3
Ibm Datapower Gateway 7.2.0.15
Ibm Datapower Gateway 7.2.0.14
Ibm Datapower Gateway 7.2.0.13
Ibm Datapower Gateway 7.2.0.12
Ibm Datapower Gateway 7.1.0.17
Ibm Datapower Gateway 7.1.0.16
Ibm Datapower Gateway 7.1.0.15
Ibm Datapower Gateway 7.1.0.14
Ibm Datapower Gateway 7.1.0.1
Ibm Datapower Gateway 7.1.0.0
Ibm Datapower Gateway 7.0.0.19
Ibm Datapower Gateway 7.0.0.18
Ibm Datapower Gateway 7.0.0.17
Ibm Datapower Gateway 7.0.0.4
Ibm Datapower Gateway 7.0.0.3
Ibm Datapower Gateway 7.0.0.2
Ibm Datapower Gateway 7.0.0.1
Ibm Datapower Gateway 7.5.2.5
4.3
CVSSv2
CVE-2013-0499
Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote malicious users to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firew...
Ibm Websphere Datapower Xc10 Appliance Firmware 3.8.2
Ibm Websphere Datapower Xc10 Appliance Firmware 4.0
Ibm Websphere Datapower Xc10 Appliance Firmware 4.0.1
Ibm Websphere Datapower Xc10 Appliance Firmware 4.0.2
Ibm Websphere Datapower Xc10 Appliance Firmware 5.0.0
Ibm Websphere Datapower Xc10 Appliance -
Ibm Websphere Datapower Service Gateway Xg45 Virtual Edition Firmware 5.0.0
Ibm Websphere Datapower Service Gateway Xg45 Virtual Edition Firmware 4.0.1
Ibm Websphere Datapower Service Gateway Xg45 Virtual Edition Firmware 4.0.2
Ibm Websphere Datapower Service Gateway Xg45 Virtual Edition Firmware 3.8.2
Ibm Websphere Datapower Service Gateway Xg45 Virtual Edition Firmware 4.0
Ibm Websphere Datapower Service Gateway Xg45 Virtual Edition -
Ibm Websphere Datapower Service Gateway Xg45 Firmware 5.0.0
Ibm Websphere Datapower Service Gateway Xg45 Firmware 3.8.2
Ibm Websphere Datapower Service Gateway Xg45 Firmware 4.0.1
Ibm Websphere Datapower Service Gateway Xg45 Firmware 4.0.2
Ibm Websphere Datapower Service Gateway Xg45 Firmware 4.0
Ibm Websphere Datapower Service Gateway Xg45 -
Ibm Websphere Datapower Integration Appliance Xi52 Virtual Edition Firmware 5.0.0
Ibm Websphere Datapower Integration Appliance Xi52 Virtual Edition Firmware 3.8.2
Ibm Websphere Datapower Integration Appliance Xi52 Virtual Edition Firmware 4.0.1
Ibm Websphere Datapower Integration Appliance Xi52 Virtual Edition Firmware 4.0.2
4
CVSSv2
CVE-2020-4203
IBM DataPower Gateway 2018.4.1.0 up to and including 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956.
Ibm Datapower Gateway
4
CVSSv2
CVE-2018-1666
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 up to and including 7.6.0.11, 7.5.2.0 up to and including 7.5.2.18, 7.5.1.0 up to and including 7.5.1.18, 7.5.0.0 up to and including 7.5.0.19, and 7.7.0.0 up to and including 7.7.1.3 could allow an authenticated user to inject arbitrary ...
Ibm Datapower Gateway
Ibm Datapower Gateway 2018.4.1.0
3.5
CVSSv2
CVE-2018-1667
IBM DataPower Gateway 7.6.0.0 up to and including 7.6.0.10, 7.5.2.0 up to and including 7.5.2.17, 7.5.1.0 up to and including 7.5.1.17, 7.5.0.0 up to and including 7.5.0.18, and 7.7.0.0 up to and including 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows u...
Ibm Datapower Gateway
2.6
CVSSv2
CVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x prior to 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote malicious users to obtain plaintext data v...
Ibm Datapower Gateway
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »