CVE-2020-5008

MEDIUM

IBM DataPower Gateway 10.0.0.0-10.0.1.0 & 2018.4.1.0-2018.4.1.14 - Sensitive Info in GET Requests

Title source: llm
STIX 2.1

Description

IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 193033.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6459681
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/193033

Scores

CVSS v3 5.3
EPSS 0.0087
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-922
Status published
Products (1)
ibm/datapower_gateway 10.0.0.0 - 10.0.1.0
Published Jun 07, 2021
Tracked Since Feb 18, 2026