CVE-2020-4205

MEDIUM

IBM DataPower Gateway 2018.4.1.0-2018.4.1.8 - Authenticated Security Restriction Bypass via Revoked Certificate

Title source: llm
STIX 2.1

Description

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.

References (2)

Core 2
Core References
Broken Link x_refsource_confirm
https://www.ibm.com/support/pages/node/6090886
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/174961

Scores

CVSS v3 6.3
EPSS 0.0053
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-287
Status published
Products (1)
ibm/datapower_gateway 2018.4.1.0 - 2018.4.1.8
Published Mar 19, 2020
Tracked Since Feb 18, 2026