IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.
2019-12-09T23:15:11.577
2024-11-21T04:43:53.167
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | datapower_gateway | ≤ 7.6.0.14 | Yes |
Application | ibm | datapower_gateway | ≤ 2018.4.1.5 | Yes |