CVE-2020-4581: High severity ibm datapower gateway 10.5.0 vulnerability
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.12 could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request. IBM X-Force ID: 184441.
Other sources
IBM DataPower Gateway could allow a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4581?
CVE-2020-4581 is a vulnerability in IBM DataPower Gateway that allows a remote attacker to cause a denial of service by sending a chunked transfer-encoding HTTP/2 request.
How does CVE-2020-4581 affect IBM DataPower Gateway?
CVE-2020-4581 affects IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.12.
What is the severity of CVE-2020-4581?
The severity of CVE-2020-4581 is high with a severity value of 7.5.
How can an attacker exploit CVE-2020-4581?
An attacker can exploit CVE-2020-4581 by sending a chunked transfer-encoding HTTP/2 request.
Is there a fix available for CVE-2020-4581?
Yes, IBM has provided a fix for CVE-2020-4581. Please refer to the IBM support page for more information.