CVE-2020-4992: CSRF
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.
Other sources
IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4992?
CVE-2020-4992 is a vulnerability in IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 that allows an attacker to execute malicious actions through cross-site request forgery.
How does the vulnerability in IBM DataPower Gateway occur?
The vulnerability occurs due to a lack of proper validation of user input, allowing an attacker to execute unauthorized actions on a trusted website.
What is the severity of CVE-2020-4992?
CVE-2020-4992 has a severity rating of 6.5 (medium).
What is the CWE ID for CVE-2020-4992?
The CWE ID for CVE-2020-4992 is CWE-352.
How can I mitigate the vulnerability in IBM DataPower Gateway?
To mitigate the vulnerability, update IBM DataPower Gateway to a version beyond 2018.4.1.16.