IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247.
2021-03-08T18:15:13.600
2024-11-21T05:33:32.830
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | datapower_gateway | ≤ 10.0.1.1 | Yes |
Application | ibm | datapower_gateway | ≤ 2018.4.1.14 | Yes |