Known vulnerabilities in IBM DataPower Gateway - page 21

Software CPE: cpe:2.3:a:ibm_corporation:ibm_datapower_gateway:*:*:*:*:*:*:*:*
Total vulnerabilities: 430
Public exploits: 19
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM DataPower Gateway IBM DataPower Gateway is affected by 430 known vulnerabilities: 1 critical, 23 high, 88 medium, 318 low Critical High Medium Low

Vulnerabilities (430)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU66858 - Cross-Site Request Forgery (CSRF)
CVE-2022-31773
CWE-352 Medium
No
No
10.0.1.10, 10.0.4.0sr2, 2018.4.1.23 30.08.2022 SB2022083028
SB2023011270
#VU63966 - NULL Pointer Dereference
CVE-2014-4344
CWE-476 Medium
No
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 03.06.2022 SB2022060309
#VU63714 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-38944
CWE-444 Medium
No
No
10.0.1.6, 10.0.4.0 26.05.2022 SB2022051848
#VU62037 - Incorrect Authorization
CVE-2022-23773
CWE-863 Low
Available
No
10.0.1.6sr1, 10.0.4.0sr1, 10.0.5.0 10.04.2022 SB2022041002
SB2022060126
SB2022060127
and 39 more
#VU60834 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-23450
CWE-94 High
No
No
10.0.1.7, 10.0.4.0sr1, 10.5.0.0, 2018.4.1.20 23.02.2022 SB2022022311
SB2022022312
SB2022031011
and 41 more
#VU57493 - Improper input validation
CVE-2021-35561
CWE-20 Medium
No
No
10.5.0.1 19.10.2021 SB2021101939
SB2021101940
SB2021102101
and 94 more
#VU54624 - Out-of-bounds read
CVE-2021-22918
CWE-125 Medium
No
No
10.0.1.5, 10.0.4.0 08.07.2021 SB2021070819
SB2021072009
SB2021081123
and 40 more
#VU52909 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7774
CWE-94 Medium
No
No
10.0.1.4, 2018.4.1.17 06.05.2021 SB2020111735
SB2021050615
SB2021092814
and 24 more
#VU51733 - NULL Pointer Dereference
CVE-2021-3449
CWE-476 Medium
Available
No
10.0.1.4, 10.0.3.0 25.03.2021 SB2021032518
SB2021032602
SB2021032617
and 56 more
#VU50745 - Improper input validation
CVE-2021-23840
CWE-20 Medium
No
No
2018.4.1.17 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 83 more
#VU49254 - Use After Free
CVE-2020-8265
CWE-416 Medium
No
No
10.0.1.4, 10.0.3.0, 2018.4.1.17 04.01.2021 SB2021010419
SB2021010704
SB2021010705
and 33 more
#VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8287
CWE-444 Medium
Available
No
10.0.1.4, 10.0.3.0, 2018.4.1.17 04.01.2021 SB2021010419
SB2021010706
SB2021010707
and 33 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Available
No
10.0.1.4, 10.0.3.0, 2018.4.1.17 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more
#VU26149 - Integer overflow
CVE-2020-10531
CWE-190 High
No
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 17.03.2020 SB2020031801
SB2020031802
SB2020031803
and 40 more
#VU23382 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10768
CWE-79 Medium
No
No
10.0.1.4, 10.0.3.0, 2018.4.1.17 04.12.2019 SB2019120407
SB2022090718
SB2022120810
and 11 more
#VU13054 - Double Free
CVE-2017-14952
CWE-415 High
No
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 30.05.2018 SB2018052513
SB2017102307
SB2017102308
and 6 more
#VU13052 - Improper input validation
CVE-2014-8147
CWE-20 High
Available
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 30.05.2018 SB2018052513
SB2015051102
SB2015070705
and 2 more
#VU13051 - Heap-based Buffer Overflow
CVE-2014-8146
CWE-122 High
Available
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 28.05.2018 SB2018052513
SB2015051102
SB2015070705
and 4 more
#VU33818 - Improper input validation
CVE-2015-2695
CWE-20 Medium
No
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 09.11.2015 SB2015110910
SB2015111601
SB2015110402
and 9 more
#VU40889 - Improper input validation
CVE-2014-5352
CWE-20 Medium
No
No
10.0.1.5, 10.0.4.0, 2018.4.1.18 19.02.2015 SB2015021906
SB2015021602
SB2015021603
and 4 more


Showing elements 401 - 420 out of 430