VulnerabilityModified
CVE-2022-22326
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks.
LOW 3.3EPSS 0.20%
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- ibm/datapower gateway · ibm/mq appliance m2002 firmware · ibm/mq appliance m2001 firmware
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/218856VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6560048Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6608598Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/218856VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6560048Patch, Vendor Advisory
- https://www.ibm.com/support/pages/node/6608598Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.