First published: Fri Jun 04 2021(Updated: )
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 193033.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | <=10.0.0.0 - 10.0.1.0 | |
IBM DataPower Gateway | <=2018.4.1.0 - 2018.4.1.14 | |
IBM DataPower Gateway | >=10.0.0.0<=10.0.1.0 | |
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5008.
The severity of CVE-2020-5008 is medium.
IBM DataPower Gateway stores sensitive information in GET request parameters, which can be accessed by unauthorized parties through server logs, referrer headers, or browser history.
IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 are affected by this vulnerability.
To fix CVE-2020-5008, it is recommended to apply the necessary security patches provided by IBM.