IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Ibm Datapower_Gateway
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
|
10.5.0.0
|
10.5.0.21
|
|
Ibm Datapower_Gateway
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
|
10.6.0.0
|
10.6.0.9
|
|
Ibm Datapower_Gateway
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:continuous_delivery:*:*:*
|
10.6.1.0
|
10.6.6.0
|