First published: Thu Aug 12 2021(Updated: )
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | <=2018.4.1.0-2018.4.1.16 | |
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4992 is a vulnerability in IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 that allows an attacker to execute malicious actions through cross-site request forgery.
The vulnerability occurs due to a lack of proper validation of user input, allowing an attacker to execute unauthorized actions on a trusted website.
CVE-2020-4992 has a severity rating of 6.5 (medium).
The CWE ID for CVE-2020-4992 is CWE-352.
To mitigate the vulnerability, update IBM DataPower Gateway to a version beyond 2018.4.1.16.