4.6
CVSSv2

CVE-2020-5014

Published: 08/03/2021 Updated: 16/03/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm datapower gateway

Github Repositories

A POC for IBM Datapower Authenticated Redis RCE Exploit abusing the Test Message Function (CVE-2020-5014)

datapower-redis-rce-exploit (CVE-2020-5014) A POC for IBM DataPower Authenticated Redis RCE Exploit abusing the "Test Message" Function Full explination and demo on Youtube Blog post on tomcopecom Explanation Using the DataPower "Send a Test Message" function available through a authenticated session to the DataPower WebGUI, it is possible to perform a SS