VulnerabilityModified
CVE-2020-4205
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked.
MEDIUM 6.3EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/datapower gateway
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/174961VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6090886Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/174961VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6090886Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.