PT-2022-20921 · Ibm · Ibm Datapower Gateway

Maxence Schmitt

+1

·

Published

2022-07-31

·

Updated

2022-08-04

·

CVE-2022-31775

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM DataPower Gateway versions 10.0.1.0 through 10.0.1.8 IBM DataPower Gateway versions 10.0.2.0 through 10.0.4.0 IBM DataPower Gateway version 10.5.0.0 IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.21
Description The issue is related to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to expose sensitive information or consume memory resources.
Recommendations For versions 10.0.1.0 through 10.0.1.8, update to a version that includes the fix for the XML External Entity Injection vulnerability. For versions 10.0.2.0 through 10.0.4.0, update to a version that includes the fix for the XML External Entity Injection vulnerability. For version 10.5.0.0, update to a version that includes the fix for the XML External Entity Injection vulnerability. For versions 2018.4.1.0 through 2018.4.1.21, update to a version that includes the fix for the XML External Entity Injection vulnerability.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-31775

Affected Products

Ibm Datapower Gateway