Known vulnerabilities in IBM DataPower Gateway - page 21
Vendor:
IBM Corporation
Software:
IBM DataPower Gateway
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_datapower_gateway:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
430
Public exploits:
19
Known exploited (KEV):
6
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
11.0.0.1
11.0.0.2
10.6.0.10
10.5.0.22
11.0.0.0
10.6.0.9
10.5.0.21
10.6.6.0
10.5.0.20
10.6.0.8
10.6.5.0
10.5.0.19
10.6.0.7
10.5.0.18
10.6.0.6
10.6.3.0
10.6.2.0
10.6.1.0
10.6.4.0
10.5.0.17
10.6.0.5
10.6.3
10.5.0.16
10.6.0.4
10.6.2
10.6.0.3
10.5.0.15
10.6.0.2
10.5.0.14
10.6.1
10.6.0.1
10.5.0.13
10.5.0.12
10.5.1.0
10.6.0.0
10.5.0.11
10.0.1.19
10.5.4
10.0.1.18
10.5.0.10
10.5.0.9
10.0.1.17
10.5.2
10.5.1
10.5.3
10.5.0.8
10.0.1.16
10.0.1.15
10.5.0.7
10.5.0.6
10.0.1.14
10.0.1.13
10.0.4.0sr3
2018.4.1.26
10.5.0.5
10.5.0.4
10.0.1.12
10.5.0.3
2018.4.1.24
10.0.1.11
10.5.0.2
10.0.4.0sr2
10.0.1.10
10.0.1.9
2018.4.1.23
2018.4.1.22
2018.4.1.19
10.5.0.1
2018.4.1.21
10.0.1.8
10.0.1.6sr1
10.0.5.0
10.5.0.0
10.0.4.0sr1
10.0.1.7
2018.4.1.20
10.0.1.4
10.0.1.3
10.0.1.2
10.0.1.1
2018.4.1.18
2018.4.1.17
2018.4.1.16
2018.4.1.15
2018.4.1.14
2018.4.1.13
2018.4.1.12
2018.4.1.11
2018.4.1.10
2018.4.1.9
2018.4.1.8
2018.4.1.7
2018.4.1.6
2018.4.1.5
2018.4.1.4
2018.4.1.3
2018.4.1.2
2018.4.1.1
2018.4.1.0
10.0.1.0
10.0.1.6
10.0.1.5
10.0.3.0
10.0.2.0
10.0.4.4
10.0.4.3
10.0.4.2
10.0.4.1
10.0.4.0
7.2.0.16
7.2.0.15
7.2.0.14
7.2.0.13
7.2.0.12
7.2.0.11
7.2.0.10
7.2.0.9
7.2.0.8
7.2.0.7
7.2.0.6
7.2.0.5
7.2.0.4
7.2.0.3
7.2.0.2
7.2.0.1
7.2.0.0
7.1.0.19
7.1.0.18
7.1.0.17
7.1.0.16
7.1.0.15
7.1.0.14
7.1.0.13
7.1.0.12
7.1.0.11
7.1.0.10
7.1.0.9
7.1.0.8
7.1.0.7
7.1.0.6
7.1.0.5
7.1.0.4
7.1.0.3
7.1.0.2
7.1.0.1
7.1.0.0
7.7.1.3
7.7.1.2
7.7.1.1
7.7.1.0
7.7.0.0
7.5.0.18
7.5.0.17
7.5.0.16
7.5.0.15
7.5.0.14
7.5.0.13
7.5.0.12
7.5.0.11
7.5.0.10
7.5.0.9
7.5.0.8
7.5.0.7
7.5.0.6
7.5.0.5
7.5.0.4
7.5.0.3
7.5.0.2
7.5.0.1
7.5.0.0
7.5.1.17
7.5.1.16
7.5.1.15
7.5.1.14
7.5.1.13
7.5.1.12
7.5.1.11
7.5.1.10
7.5.1.9
7.5.1.8
7.5.1.7
7.5.1.6
7.5.1.5
7.5.1.4
7.5.1.3
7.5.1.2
7.5.1.1
7.5.1.0
7.5.2.17
7.5.2.16
7.5.2.15
7.5.2.14
7.5.2.13
7.5.2.12
7.5.2.11
7.5.2.10
7.5.2.9
7.5.2.8
7.5.2.7
7.5.2.6
7.5.2.5
7.5.2.4
7.5.2.3
7.5.2.2
7.5.2.1
7.5.2.0
7.6.0.10
7.6.0.9
7.6.0.8
7.6.0.7
7.6.0.6
7.6.0.5
7.6.0.4
7.6.0.3
7.6.0.2
7.6.0.1
7.6.0.0
7.7
7.2
7.1
7.6
7.5.2
7.5.1
7.5
Vulnerabilities (430)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU66858 - Cross-Site Request Forgery (CSRF) CVE-2022-31773 |
CWE-352 | Medium | 10.0.1.10, 10.0.4.0sr2, 2018.4.1.23 | 30.08.2022 |
SB2022083028 SB2023011270 |
||
| #VU63966 - NULL Pointer Dereference CVE-2014-4344 |
CWE-476 | Medium | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 03.06.2022 |
SB2022060309 |
||
| #VU63714 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-38944 |
CWE-444 | Medium | 10.0.1.6, 10.0.4.0 | 26.05.2022 |
SB2022051848 |
||
| #VU62037 - Incorrect Authorization CVE-2022-23773 |
CWE-863 | Low | 10.0.1.6sr1, 10.0.4.0sr1, 10.0.5.0 | 10.04.2022 |
SB2022041002 SB2022060126 SB2022060127 and 39 more |
||
| #VU60834 - Improper Control of Generation of Code ('Code Injection') CVE-2021-23450 |
CWE-94 | High | 10.0.1.7, 10.0.4.0sr1, 10.5.0.0, 2018.4.1.20 | 23.02.2022 |
SB2022022311 SB2022022312 SB2022031011 and 41 more |
||
| #VU57493 - Improper input validation CVE-2021-35561 |
CWE-20 | Medium | 10.5.0.1 | 19.10.2021 |
SB2021101939 SB2021101940 SB2021102101 and 94 more |
||
| #VU54624 - Out-of-bounds read CVE-2021-22918 |
CWE-125 | Medium | 10.0.1.5, 10.0.4.0 | 08.07.2021 |
SB2021070819 SB2021072009 SB2021081123 and 40 more |
||
| #VU52909 - Improper Control of Generation of Code ('Code Injection') CVE-2020-7774 |
CWE-94 | Medium | 10.0.1.4, 2018.4.1.17 | 06.05.2021 |
SB2020111735 SB2021050615 SB2021092814 and 24 more |
||
| #VU51733 - NULL Pointer Dereference CVE-2021-3449 |
CWE-476 | Medium | 10.0.1.4, 10.0.3.0 | 25.03.2021 |
SB2021032518 SB2021032602 SB2021032617 and 56 more |
||
| #VU50745 - Improper input validation CVE-2021-23840 |
CWE-20 | Medium | 2018.4.1.17 | 17.02.2021 |
SB2021021702 SB2021021817 SB2021022420 and 83 more |
||
| #VU49254 - Use After Free CVE-2020-8265 |
CWE-416 | Medium | 10.0.1.4, 10.0.3.0, 2018.4.1.17 | 04.01.2021 |
SB2021010419 SB2021010704 SB2021010705 and 33 more |
||
| #VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-8287 |
CWE-444 | Medium | 10.0.1.4, 10.0.3.0, 2018.4.1.17 | 04.01.2021 |
SB2021010419 SB2021010706 SB2021010707 and 33 more |
||
| #VU48896 - NULL Pointer Dereference CVE-2020-1971 |
CWE-476 | Medium | 10.0.1.4, 10.0.3.0, 2018.4.1.17 | 08.12.2020 |
SB2020120852 SB2020120903 SB2020120905 and 91 more |
||
| #VU26149 - Integer overflow CVE-2020-10531 |
CWE-190 | High | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 17.03.2020 |
SB2020031801 SB2020031802 SB2020031803 and 40 more |
||
| #VU23382 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-10768 |
CWE-79 | Medium | 10.0.1.4, 10.0.3.0, 2018.4.1.17 | 04.12.2019 |
SB2019120407 SB2022090718 SB2022120810 and 11 more |
||
| #VU13054 - Double Free CVE-2017-14952 |
CWE-415 | High | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 30.05.2018 |
SB2018052513 SB2017102307 SB2017102308 and 6 more |
||
| #VU13052 - Improper input validation CVE-2014-8147 |
CWE-20 | High | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 30.05.2018 |
SB2018052513 SB2015051102 SB2015070705 and 2 more |
||
| #VU13051 - Heap-based Buffer Overflow CVE-2014-8146 |
CWE-122 | High | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 28.05.2018 |
SB2018052513 SB2015051102 SB2015070705 and 4 more |
||
| #VU33818 - Improper input validation CVE-2015-2695 |
CWE-20 | Medium | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 09.11.2015 |
SB2015110910 SB2015111601 SB2015110402 and 9 more |
||
| #VU40889 - Improper input validation CVE-2014-5352 |
CWE-20 | Medium | 10.0.1.5, 10.0.4.0, 2018.4.1.18 | 19.02.2015 |
SB2015021906 SB2015021602 SB2015021603 and 4 more |
Showing elements 401 - 420 out of 430