Authentication Bypass Vulnerability in IBM DataPower Gateway
CVE-2020-4205
5MEDIUM
Summary
The IBM DataPower Gateway versions from 2018.4.1.0 to 2018.4.1.8 are susceptible to an authentication bypass vulnerability. This flaw enables an authenticated user to circumvent security restrictions. Consequently, users can gain unauthorized access to the server even when their authentication certificates have been revoked, exposing critical information and processes to potential exploitation. Users and administrators must take immediate action to secure their systems against this vulnerability. For more details, check the IBM support page and the X-Force exchange entry.
Affected Version(s)
DataPower Gateway 2018.4.1.0
DataPower Gateway 2018.4.1.8
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved