IBM Application Gateway could disclose sensitive information in HTTP server headers that could be used in further attacks against the system.
IBM Application Gateway could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
IBM Application Gateway allows web pages to be stored locally which can be read by another user on the system.