IBM Application Gateway could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
IBM Application Gateway allows web pages to be stored locally which can be read by another user on the system.
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.