VYPR

Datapower Gateway

by IBM

CVEs (43)

  • CVE-2025-36374MedJul 30, 2026
    risk 0.00cvss 5.5epss 0.00

    IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2015-7427Nov 14, 2015
    risk 0.00cvss epss 0.01

    IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers…

  • CVE-2015-7412Nov 8, 2015
    risk 0.00cvss epss 0.01

    The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a…

Page 3 of 3