First published: Tue Feb 08 2022(Updated: )
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=10.0.1.0<10.0.1.6 | |
IBM DataPower Gateway | >=10.0.2.0<10.0.5.0 | |
IBM DataPower Gateway | >=2018.4.1.0<2018.4.1.19 | |
Ibm Mq Appliance M2002 Firmware | <9.2.0.5 | |
Ibm Mq Appliance M2002 Firmware | <9.2.5 | |
Ibm Mq Appliance M2002 | ||
Ibm Mq Appliance M2001 Firmware | <9.2.0.5 | |
Ibm Mq Appliance M2001 Firmware | <9.2.5 | |
Ibm Mq Appliance M2001 | ||
IBM MQ Appliance | <=9.2 CD | |
IBM MQ Appliance | <=9.2 LTS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22326.
The severity of CVE-2022-22326 is medium.
IBM DataPower Gateway V10CD, IBM DataPower Gateway 10.0.1, and IBM DataPower Gateway 2018.4.1 are affected by CVE-2022-22326.
CVE-2022-22326 could allow unauthorized viewing of logs and files due to insufficient authorization checks.
You can find more information about CVE-2022-22326 at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/218856), [Link 2](https://www.ibm.com/support/pages/node/6608598), [Link 3](https://www.ibm.com/support/pages/node/6560048).