Skip to main content

Vendor/product archive

ibm / datapower_gateway CVEs

Beta · best-effort

41 CVEs tagged to ibm / datapower_gateway2 Critical, 12 High, 24 Medium, 3 Low, 0 Unrated.

CVE-2026-12733

Published Jul 30, 2026

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36375

Published Apr 1, 2026

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM D…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36373

Published Apr 1, 2026

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM D…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-40228

Published Nov 22, 2022

IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a passw…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-31773

Published Aug 26, 2022

IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitt…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32750

Published Aug 1, 2022

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31776

Published Aug 1, 2022

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31775

Published Aug 1, 2022

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) at…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31774

Published Aug 1, 2022

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38944

Published May 18, 2022

IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38872

Published May 17, 2022

IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resourc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4994

Published May 17, 2022

IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP request…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38910

Published Mar 10, 2022

IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4992

Published Aug 17, 2021

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5008

Published Jun 7, 2021

IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4831

Published Mar 12, 2021

IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Forc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5014

Published Mar 8, 2021

IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack.…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4528

Published Oct 6, 2020

IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information fro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4581

Published Sep 21, 2020

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4580

Published Sep 21, 2020

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4579

Published Sep 21, 2020

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4205

Published Mar 19, 2020

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4203

Published Mar 19, 2020

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 1…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4621

Published Dec 9, 2019

IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2