CVE-2021-38910: Input Validation
IBM DataPower Gateway could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could exploit this vulnerability to modify structure and fields.
Other sources
IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. By sending a specially crafted JSON message, an attacker could exploit this vulnerability to modify structure and fields. IBM X-Force ID: 209824.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this IBM DataPower Gateway vulnerability?
The vulnerability ID of this IBM DataPower Gateway vulnerability is CVE-2021-38910.
What is the severity of CVE-2021-38910?
The severity of CVE-2021-38910 is medium with a severity value of 5.3.
How can a remote attacker exploit CVE-2021-38910?
A remote attacker can exploit CVE-2021-38910 by sending a specially crafted JSON message to bypass security restrictions and modify structure and fields.
Which versions of IBM DataPower Gateway are affected by CVE-2021-38910?
IBM DataPower Gateway versions 10.0.1 and 2108.4.1, as well as IBM DataPower Gateway V10CD versions 10.0.2.0 and 10.0.3.0 are affected by CVE-2021-38910.
Is there a fix available for CVE-2021-38910?
Yes, IBM has released a fix for CVE-2021-38910. Please refer to the IBM Support page for more information.