CVE-2018-1666

MEDIUM

IBM DataPower Gateway - Auth Bypass

Title source: llm
STIX 2.1

Description

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10744205
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/144892

Scores

CVSS v3 4.3
EPSS 0.0084
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (2)
ibm/datapower_gateway 2018.4.1.0
ibm/datapower_gateway 7.5.0.0 - 7.5.0.19
Published Feb 07, 2019
Tracked Since Feb 18, 2026