First published: Fri Sep 18 2020(Updated: )
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters. IBM X-Force ID: 184438.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.12 | |
<=2018.4.1.0-2018.4.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM DataPower Gateway vulnerability is CVE-2020-4579.
The severity level of CVE-2020-4579 is high, with a CVSS score of 7.5.
CVE-2020-4579 could allow a remote attacker to cause a denial of service by sending a specially crafted HTTP/2 request with invalid characters.
IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.12 are affected by CVE-2020-4579.
Ensure you have installed the necessary patches or updates provided by IBM to fix CVE-2020-4579 in IBM DataPower Gateway.