Vulnerabilities > IBM > Datapower Gateway > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-19 CVE-2020-4203 Unspecified vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls.
network
low complexity
ibm
4.9
2019-02-07 CVE-2018-1666 Unspecified vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI.
network
low complexity
ibm
4.3
2018-12-20 CVE-2018-1677 Improper Handling of Exceptional Conditions vulnerability in IBM Datapower Gateway
IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system.
local
low complexity
ibm CWE-755
5.5
2018-12-13 CVE-2018-1667 Cross-site Scripting vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-12-11 CVE-2018-1652 Improper Input Validation vulnerability in IBM Datapower Gateway
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors.
local
low complexity
ibm CWE-20
5.5
2018-12-07 CVE-2018-1663 Information Exposure vulnerability in IBM Datapower Gateway
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-200
5.9
2018-01-31 CVE-2017-1773 Insufficient Verification of Data Authenticity vulnerability in IBM Datapower Gateway
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic.
network
high complexity
ibm CWE-345
4.0
2017-09-28 CVE-2017-1591 Cross-site Scripting vulnerability in IBM Datapower Gateway
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1