First published: Tue Mar 17 2020(Updated: )
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.8 | |
<=2018.4.1.0-2018.4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4205 is a vulnerability in IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 that allows an authenticated user to bypass security restrictions and continue accessing the server even after authentication certificates have been revoked.
The severity of CVE-2020-4205 is medium, with a severity value of 6.3.
CVE-2020-4205 affects IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8, allowing an authenticated user to bypass security restrictions.
To fix CVE-2020-4205, upgrade IBM DataPower Gateway to a version outside the vulnerable range (2018.4.1.0-2018.4.1.8).
You can find more information about CVE-2020-4205 at the IBM X-Force ID (174961) and the IBM support page.