CVE-2022-22326

Severity
3.3LOW
EPSS
0.1%
top 82.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateAug 2

Description

IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

NVDibm/datapower_gateway10.0.1.010.0.1.6+2
CVEListV5ibm/datapower_gateway6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h43r-9pq6-rj78: IBM Datapower Gateway 102022-08-02
CVEList
CVE-2022-22326: IBM Datapower Gateway 102022-07-31
CVE-2022-22326 (LOW CVSS 3.3) | IBM Datapower Gateway 10.0.2.0 thro | cvebase.io