First published: Fri Jul 29 2022(Updated: )
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 228433.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=10.0.1.0<=10.0.1.8 | |
IBM DataPower Gateway | >=10.0.2.0<10.5.0.1 | |
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.21 | |
IBM DataPower Gateway | =10.5.0.0 | |
IBM DataPower Gateway 10.5.0 | <=10.5.0.0 | |
IBM DataPower Gateway V10CD | <=10.0.2.0 - 10.0.4.0 | |
IBM DataPower Gateway 10.0.1 | <=10.0.1.0 - 10.0.1.8 | |
IBM DataPower Gateway | <=2018.4.1.0 - 2018.4.1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31776 is a vulnerability in IBM DataPower Gateway that allows an authenticated attacker to perform server-side request forgery (SSRF).
CVE-2022-31776 has a severity rating of 8.8, which is considered high.
CVE-2022-31776 affects IBM DataPower Gateway versions 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21.
Server-side request forgery (SSRF) is a vulnerability that allows an attacker to make unauthorized requests from the server to other internal or external systems.
To mitigate the CVE-2022-31776 vulnerability, it is recommended to apply the necessary patches or updates provided by IBM.