Vulnerabilities > IBM > Datapower Gateway > 10.0.4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-11-22 | CVE-2022-40228 | Insufficient Session Expiration vulnerability in IBM Datapower Gateway IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. | 5.4 |
2022-08-01 | CVE-2022-22326 | Incorrect Authorization vulnerability in IBM products IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. | 3.3 |