Authentication Bypass Vulnerability in IBM DataPower Gateway
CVE-2020-4205

5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
19 March 2020

Summary

The IBM DataPower Gateway versions from 2018.4.1.0 to 2018.4.1.8 are susceptible to an authentication bypass vulnerability. This flaw enables an authenticated user to circumvent security restrictions. Consequently, users can gain unauthorized access to the server even when their authentication certificates have been revoked, exposing critical information and processes to potential exploitation. Users and administrators must take immediate action to secure their systems against this vulnerability. For more details, check the IBM support page and the X-Force exchange entry.

Affected Version(s)

DataPower Gateway 2018.4.1.0

DataPower Gateway 2018.4.1.8

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.