CVE-2021-38872: High severity ibm datapower gateway 10.5.0 vulnerability
IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348.
Other sources
IBM DataPower Gateway could allow a remote user to cause a denial of service by consuming resources with multiple requests.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-38872?
CVE-2021-38872 is a vulnerability in IBM DataPower Gateway that could allow a remote user to cause a denial of service by consuming resources with multiple requests.
Which versions of IBM DataPower Gateway are affected by CVE-2021-38872?
IBM DataPower Gateway versions 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 are affected by CVE-2021-38872.
What is the severity of CVE-2021-38872?
CVE-2021-38872 has a severity level of 7.5 (High).
How can a remote user exploit CVE-2021-38872?
A remote user can exploit CVE-2021-38872 by sending multiple requests to consume system resources and cause a denial of service.
Is there a solution for CVE-2021-38872?
Yes, IBM has provided a solution for CVE-2021-38872. Please refer to the IBM support page for more information.