CVE-2020-4994: High severity IBM DataPower Gateway vulnerability
IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.
Other sources
IBM DataPower Gateway could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-4994?
CVE-2020-4994 is a vulnerability in IBM DataPower Gateway that could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests.
What is the severity level of CVE-2020-4994?
The severity of CVE-2020-4994 is high with a CVSS score of 7.5.
Which versions of IBM DataPower Gateway are affected by CVE-2020-4994?
IBM DataPower Gateway versions 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 are affected by CVE-2020-4994.
How can a remote user exploit CVE-2020-4994?
A remote user can exploit CVE-2020-4994 by sending invalid HTTP requests.
Is there a fix available for CVE-2020-4994?
Yes, IBM has provided a fix for CVE-2020-4994. Please refer to the IBM support page for more information.