VYPR

Datapower Gateway

by IBM

CVEs (43)

  • CVE-2019-4621CriDec 9, 2019
    risk 0.64cvss 9.8epss 0.02

    IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.

  • CVE-2022-31775CriAug 1, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…

  • CVE-2022-31773HigAug 26, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357.

  • CVE-2022-31776HigAug 1, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially…

  • CVE-2019-4294HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection…

  • CVE-2026-12733HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

  • CVE-2021-38872HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348.

  • CVE-2020-4994HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.

  • CVE-2020-4831HigMar 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 189965.

  • CVE-2020-4581HigSep 21, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441.

  • CVE-2020-4580HigSep 21, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439.

  • CVE-2020-4579HigSep 21, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.

  • CVE-2018-1669HigSep 25, 2018
    risk 0.46cvss 7.1epss 0.02

    IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing…

  • CVE-2018-1421HigApr 4, 2018
    risk 0.46cvss 7.1epss 0.01

    IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM…

  • CVE-2020-5014MedMar 8, 2021
    risk 0.44cvss 6.7epss 0.01

    IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247.

  • CVE-2025-36375MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to…

  • CVE-2020-4992MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.

  • CVE-2018-1661MedDec 20, 2018
    risk 0.42cvss 6.5epss 0.01

    IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.

  • CVE-2020-4205MedMar 19, 2020
    risk 0.41cvss 6.3epss 0.01

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.

  • CVE-2021-38944MedMay 18, 2022
    risk 0.40cvss 6.1epss 0.01

    IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the…

Page 1 of 3