Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-5008


IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 193033.


Published

2021-06-07T14:15:07.717

Last Modified

2024-11-21T05:33:32.600

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-922

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm datapower_gateway ≤ 10.0.1.0 Yes
Application ibm datapower_gateway ≤ 2018.4.1.14 Yes

References