CVE-2020-5014: SSRF
IBM DataPower Gateway could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack.
Other sources
IBM DataPower Gateway V10 and V2018 could allow a local attacker with administrative privileges to execute arbitrary code on the system using a server-side requesr forgery attack. IBM X-Force ID: 193247.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5014?
CVE-2020-5014 has a critical severity rating due to its potential for arbitrary code execution by a local attacker with administrative privileges.
How do I fix CVE-2020-5014?
To fix CVE-2020-5014, upgrade IBM DataPower Gateway to version 10.0.1.1 or higher, or to version 2018.4.1.15 or higher.
Who is affected by CVE-2020-5014?
CVE-2020-5014 affects IBM DataPower Gateway versions 10.0.0.0 to 10.0.1.1 and 2018.4.1.0 to 2018.4.1.14.
What type of attack does CVE-2020-5014 involve?
CVE-2020-5014 involves a server-side request forgery (SSRF) attack that allows unauthorized code execution.
Can CVE-2020-5014 be exploited remotely?
No, CVE-2020-5014 requires local administrative access to exploit the vulnerability.