Ibm Datapower Gateway vulnerabilities
40 known vulnerabilities affecting ibm/datapower_gateway.
Total CVEs
40
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM20LOW2
Vulnerabilities
Page 1 of 2
CVE-2019-4621P3CRITICALCVSS 9.8≥ 7.6.0.0, ≤ 7.6.0.14≥ 2018.4.1.0, ≤ 2018.4.1.5+4 more2019-12-09
CVE-2019-4621 [CRITICAL] CWE-1188 CVE-2019-4621: IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default admin
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.
nvd
CVE-2022-31776P3HIGHCVSS 8.8≥ 10.0.1.0, ≤ 10.0.1.8≥ 10.0.2.0, < 10.5.0.1+8 more2022-08-01
CVE-2022-31776 [HIGH] CWE-918 CVE-2022-31776: IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 2
nvd
CVE-2022-31775P3CRITICALCVSS 9.1≥ 10.0.1.0, < 10.0.1.8≥ 10.0.2.0, < 10.5.0.1+8 more2022-08-01
CVE-2022-31775 [CRITICAL] CWE-611 CVE-2022-31775: IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228359.
nvd
CVE-2025-36375P3HIGHCVSS 8.8≥ 10.5.0.0, < 10.5.0.21≥ 10.6.0.0, < 10.6.0.9+1 more2026-04-01
CVE-2025-36375 [HIGH] CWE-352 CVE-2025-36375: IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 thr
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the webs
nvd
CVE-2019-4294P3HIGHCVSS 7.8fixed in 2018.4.1.7≥ 7.6.0.0, ≤ 7.6.0.15+6 more2019-08-20
CVE-2019-4294 [HIGH] CWE-78 CVE-2019-4294: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.
nvd
CVE-2018-1669P3HIGHCVSS 7.1≥ 7.1.0.0, ≤ 7.1.0.23≥ 7.2.0.0, ≤ 7.2.0.21+5 more2018-09-25
CVE-2018-1669 [HIGH] CWE-611 CVE-2018-1669: IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensiti
nvd
CVE-2022-31773P3HIGHCVSS 8.8≥ 10.0.1.0, < 10.5.0≥ 10.0.2.0, < 10.5.0+7 more2022-08-26
CVE-2022-31773 [HIGH] CWE-352 CVE-2022-31773: IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which
IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357.
nvd
CVE-2018-1421P3HIGHCVSS 7.1≥ 7.1.0.0, ≤ 7.1.0.21≥ 7.2.0.0, ≤ 7.2.0.18+4 more2018-04-04
CVE-2018-1421 [HIGH] CWE-611 CVE-2018-1421: IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML Exter
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023.
nvd
CVE-2020-4579P3HIGHCVSS 7.5≥ 2018.4.1.0, ≤ 2018.4.1.12v2018.4.1.0+1 more2020-09-21
CVE-2020-4579 [HIGH] CVE-2020-4579: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.
nvd
CVE-2021-38872P3HIGHCVSS 7.5≥ 10.0.1.0, ≤ 10.0.1.4≥ 2018.4.1.0, ≤ 2018.4.1.17+6 more2022-05-17
CVE-2021-38872 [HIGH] CVE-2021-38872: IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1
IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348.
nvd
CVE-2018-1668P3HIGHCVSS 7.5≥ 7.5.0.0, ≤ 7.5.0.19≥ 7.5.1.0, ≤ 7.5.1.18+10 more2019-01-29
CVE-2018-1668 [HIGH] CWE-287 CVE-2018-1668: IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18,
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.
nvd
CVE-2020-4831P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.1.0v10.0.0.0+1 more2021-03-12
CVE-2020-4831 [HIGH] CWE-327 CVE-2020-4831: IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms t
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 189965.
nvd
CVE-2020-4580P3HIGHCVSS 7.5≥ 2018.4.1.0, ≤ 2018.4.1.12v2018.4.1.0+1 more2020-09-21
CVE-2020-4580 [HIGH] CVE-2020-4580: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439.
nvd
CVE-2020-4994P3HIGHCVSS 7.5≥ 10.0.1.0, ≤ 10.0.1.4≥ 2018.4.1.0, ≤ 2018.4.1.17+4 more2022-05-17
CVE-2020-4994 [HIGH] CVE-2020-4994: IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a rem
IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.
nvd
CVE-2018-1665P3HIGHCVSS 7.5≥ 7.5.0.0, ≤ 7.5.0.18≥ 7.5.1.0, ≤ 7.5.1.17+13 more2018-12-13
CVE-2018-1665 [HIGH] CWE-326 CVE-2018-1665: IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17,
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144891.
nvd
CVE-2018-1661P3HIGHCVSS 8.8≥ 7.5.0.0, ≤ 7.5.0.17≥ 7.5.1.0, ≤ 7.5.1.16+2 more2018-12-20
CVE-2018-1661 [HIGH] CWE-352 CVE-2018-1661: IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.
nvd
CVE-2020-4581P3HIGHCVSS 7.5≥ 2018.4.1.0, ≤ 2018.4.1.12v2018.4.1.0+1 more2020-09-21
CVE-2020-4581 [HIGH] CVE-2020-4581: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441.
nvd
CVE-2018-1664P3HIGHCVSS 7.8≥ 7.1.0.0, ≤ 7.1.0.23≥ 7.2.0.0, ≤ 7.2.0.21+5 more2018-09-25
CVE-2018-1664 [HIGH] CVE-2018-1664: IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.
nvd
CVE-2025-36373P4MEDIUMCVSS 6.8≥ 10.5.0.0, < 10.5.0.21≥ 10.6.0.0, < 10.6.0.9+1 more2026-04-01
CVE-2025-36373 [MEDIUM] CWE-497 CVE-2025-36373: IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 thr
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.
nvd
CVE-2020-4205P4MEDIUMCVSS 6.3≥ 2018.4.1.0, ≤ 2018.4.1.8v2018.4.1.0+1 more2020-03-19
CVE-2020-4205 [MEDIUM] CWE-287 CVE-2020-4205: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass secu
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.
nvd
1 / 2Next →