PT-2022-20922 · Ibm · Ibm Datapower Gateway

Maxence Schmitt

+1

·

Published

2022-07-31

·

Updated

2022-08-04

·

CVE-2022-31776

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DataPower Gateway versions 10.0.1.0 through 10.0.1.8 IBM DataPower Gateway versions 10.0.2.0 through 10.0.4.0 IBM DataPower Gateway version 10.5.0.0 IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.21
Description The issue is related to server-side request forgery (SSRF), which may allow an authenticated attacker to send unauthorized requests from the system. This could potentially lead to network enumeration or facilitate other attacks.
Recommendations For versions 10.0.1.0 through 10.0.1.8, update to a version outside of this range to resolve the issue. For versions 10.0.2.0 through 10.0.4.0, update to a version outside of this range to resolve the issue. For version 10.5.0.0, update to a newer version to resolve the issue. For versions 2018.4.1.0 through 2018.4.1.21, update to a version outside of this range to resolve the issue.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-31776

Affected Products

Ibm Datapower Gateway