IBM
IBM Datapower Gateway: vulnerabilidades y CVE
IBM Datapower Gateway tiene 43 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE43
Últimos 12 meses5
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-7366 | Media (4.2) | 0.16% | — | 12 ago 2026 | IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of… |
| CVE-2026-12733 | Alta (7.5) | 0.55% | — | 30 jul 2026 | IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. |
| CVE-2025-36374 | Media (5.5) | 0.42% | — | 30 jul 2026 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory… |
| CVE-2025-36375 | Alta (8.8) | 0.17% | — | 1 abr 2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to… |
| CVE-2025-36373 | Media (6.8) | 0.25% | — | 1 abr 2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose… |
| CVE-2022-40228 | Media (5.4) | 0.34% | — | 22 nov 2022 | IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.0.0 through 10.5.0.2 does not invalidate session after a password change which could allow an… |
| CVE-2022-31773 | Alta (8.8) | 0.42% | — | 26 ago 2022 | IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.… |
| CVE-2022-32750 | Media (5.4) | 0.48% | — | 1 ago 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary… |
| CVE-2022-31776 | Alta (8.8) | 0.54% | — | 1 ago 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to… |
| CVE-2022-31775 | Crítica (9.1) | 1.5% | — | 1 ago 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote… |
| CVE-2022-31774 | Media (5.4) | 0.48% | — | 1 ago 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary… |
| CVE-2022-22326 | Baja (3.3) | 0.20% | — | 1 ago 2022 | IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID:… |
| CVE-2021-38944 | Media (6.1) | 0.58% | — | 18 may 2022 | IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This… |
| CVE-2021-38872 | Alta (7.5) | 1.5% | — | 17 may 2022 | IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force… |
| CVE-2020-4994 | Alta (7.5) | 1.5% | — | 17 may 2022 | IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906. |
| CVE-2021-38910 | Media (5.3) | 1.1% | — | 10 mar 2022 | IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could… |
| CVE-2020-4992 | Media (6.5) | 0.40% | — | 17 ago 2021 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website… |
| CVE-2020-5008 | Media (5.3) | 0.87% | — | 7 jun 2021 | IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to… |
| CVE-2020-4831 | Alta (7.5) | 0.77% | — | 12 mar 2021 | IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 189965. |
| CVE-2020-5014 | Media (6.7) | 0.87% | — | 8 mar 2021 | IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247. |
| CVE-2020-4528 | Media (5.5) | 0.29% | — | 6 oct 2020 | IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658. |
| CVE-2020-4581 | Alta (7.5) | 1.6% | — | 21 sept 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441. |
| CVE-2020-4580 | Alta (7.5) | 1.6% | — | 21 sept 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted a JSON request with invalid characters. IBM X-Force ID: 184439. |
| CVE-2020-4579 | Alta (7.5) | 2.2% | — | 21 sept 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438. |
| CVE-2020-4205 | Media (6.3) | 0.53% | — | 19 mar 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM… |
| CVE-2020-4203 | Media (4.9) | 1.3% | — | 19 mar 2020 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956. |
| CVE-2019-4621 | Crítica (9.8) | 1.6% | — | 9 dic 2019 | IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain… |
| CVE-2019-4294 | Alta (7.8) | 0.95% | — | 20 ago 2019 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute… |
| CVE-2018-1666 | Media (4.3) | 0.84% | — | 7 feb 2019 | IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary… |
| CVE-2018-1668 | Alta (7.5) | 1.4% | — | 29 ene 2019 | IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142