Ibm Datapower Gateways vulnerabilities

10 known vulnerabilities affecting ibm/datapower_gateways.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2018-1661HIGHCVSS 8.8v7.5v7.5.1+2 more2018-12-20
CVE-2018-1661 [MEDIUM] CWE-352 CVE-2018-1661: IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.
cvelistv5nvd
CVE-2018-1677MEDIUMCVSS 5.5v7.1v7.2+5 more2018-12-20
CVE-2018-1677 [MEDIUM] CWE-755 CVE-2018-1677: IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 145171.
cvelistv5nvd
CVE-2018-1667MEDIUMCVSS 5.4v7.5.0.0v7.5.1.0+8 more2018-12-13
CVE-2018-1667 [MEDIUM] CWE-79 CVE-2018-1667: IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl
cvelistv5nvd
CVE-2018-1652MEDIUMCVSS 5.5v7.1.0.0v7.2.0.0+10 more2018-12-11
CVE-2018-1652 [MEDIUM] CWE-20 CVE-2018-1652: IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
cvelistv5nvd
CVE-2018-1663MEDIUMCVSS 5.9v7.5v7.5.1+3 more2018-12-07
CVE-2018-1663 [MEDIUM] CWE-200 CVE-2018-1663: IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain se IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889.
cvelistv5nvd
CVE-2018-1669HIGHCVSS 7.1v7.1.0.0v7.1.0.23+10 more2018-09-25
CVE-2018-1669 [HIGH] CWE-611 CVE-2018-1669: IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15 IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensiti
cvelistv5nvd
CVE-2018-1664HIGHCVSS 7.8v7.1.0.0v7.1.0.23+10 more2018-09-25
CVE-2018-1664 [MEDIUM] CVE-2018-1664: IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15 IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.
cvelistv5nvd
CVE-2018-1421HIGHCVSS 7.1v7.1v7.2+4 more2018-04-04
CVE-2018-1421 [HIGH] CWE-611 CVE-2018-1421: IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML Exter IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023.
cvelistv5nvd
CVE-2017-1773MEDIUMCVSS 4.0v7.1v7.2+4 more2018-01-31
CVE-2017-1773 [MEDIUM] CWE-345 CVE-2017-1773: IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techni IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
cvelistv5nvd
CVE-2017-1591MEDIUMCVSS 6.1v7.0.0v7.1+5 more2017-09-28
CVE-2017-1591 [MEDIUM] CWE-79 CVE-2017-1591: IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vul IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368.
cvelistv5nvd