CVE-2019-4621: Critical severity IBM DataPower Gateway vulnerability
IBM DataPower Appliance and IBM MQ Appliance have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC.
Other sources
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-4621.
What is the severity level of CVE-2019-4621?
The severity level of CVE-2019-4621 is critical.
Which products are affected by CVE-2019-4621?
IBM DataPower Gateway versions 7.6.0.0-7.6.0.14 and 2018.4.1.0-2018.4.1.5 are affected by CVE-2019-4621.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by using the default administrator account to gain unauthorized access to the BMC.
Is there a fix or patch available for CVE-2019-4621?
Yes, IBM has provided a fix for CVE-2019-4621. Please refer to the IBM support page for more information.