
CVE-2018-1663
https://notcve.org/view.php?id=CVE-2018-1663
07 Dec 2018 — IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889. IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6 y 2018.4 podría permitir que un atacante remoto obtenga información sensible, provocado por la imposibilidad de habilitar correctamente... • http://www.securityfocus.com/bid/106199 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-1664
https://notcve.org/view.php?id=CVE-2018-1664
25 Sep 2018 — IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890. En IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15 y 7.6.0.0 - 7.6.0.8, así como IBM DataPower Gateway CD 7.7.0.0 -... • https://exchange.xforce.ibmcloud.com/vulnerabilities/144890 •

CVE-2018-1669
https://notcve.org/view.php?id=CVE-2018-1669
25 Sep 2018 — IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 144950. IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0... • https://exchange.xforce.ibmcloud.com/vulnerabilities/144950 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2018-1421
https://notcve.org/view.php?id=CVE-2018-1421
04 Apr 2018 — IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023. Las versiones 7.1, 7.2, 7.5, 7.5.1, 7.5.2 y 7.6 de IBM WebSphere DataPower Appliances son vulnerables a ataques de tipo XML External Entity Injection (XXE) al procesar datos XML. Un atacante remoto podría explotar es... • http://www.ibm.com/support/docview.wss?uid=swg22015055 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2017-1773
https://notcve.org/view.php?id=CVE-2017-1773
31 Jan 2018 — IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817. IBM DataPower Gateways 7.1, 7,2, 7.5 y 7.6 podría permitir que un atacante que emplee técnicas de Man-in-the-Middle (MitM) suplante las respuestas DNS para realizar envenenamiento de caché DNS y redireccionar el tráfico de Internet. IBM X-Force ID: 136817. • http://www.ibm.com/support/docview.wss?uid=swg22012758 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2017-1591
https://notcve.org/view.php?id=CVE-2017-1591
27 Sep 2017 — IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368. IBM WebSphere DataPower Appliances versión 7.0.0 hasta 7.6, es vulnerable a ataques de tipo cross-site scripting. Esta vulnerabilidad permite a los usuarios insertar código JavaScript arbitrario en la i... • http://www.ibm.com/support/docview.wss?uid=swg22008815 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-7427
https://notcve.org/view.php?id=CVE-2015-7427
14 Nov 2015 — IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session. Dispositivos IBM DataPower Gateway con firmware 6.x en versiones anteriores a 6.0.0.17, 6.0.1.x en versiones anteriores a 6.0.1.17, 7.x en versiones a... • http://www-01.ibm.com/support/docview.wss?uid=swg1IT10279 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2015-7412
https://notcve.org/view.php?id=CVE-2015-7412
08 Nov 2015 — The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack. Los módulos GatewayScript en IBM DataPower Gateways con software 7.2.0.x en versiones anteriores a 7.2.0.1, cuando la API de descifrado GatewayScript o una acción de descifrado JWE está activada, no requiere dato... • http://www-01.ibm.com/support/docview.wss?uid=swg1IT10701 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2013-0499 – IBM WebSphere DataPower 3.8.2 / 4.0.x / 5.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2013-0499
23 May 2013 — Cross-site scripting (XSS) vulnerability in the echo functionality on IBM WebSphere DataPower SOA appliances with firmware 3.8.2, 4.0, 4.0.1, 4.0.2, and 5.0.0 allows remote attackers to inject arbitrary web script or HTML via a SOAP message, as demonstrated by the XML Firewall, Multi Protocol Gateway (MPGW), Web Service Proxy, and Web Token services. Una vulnerabilidad de tipo cross-site scripting (XSS) en la funcionalidad echo en dispositivos SOA WebSphere DataPower de IBM con la versión de firmware 3.8.2,... • http://seclists.org/bugtraq/2013/May/83 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2010-1612
https://notcve.org/view.php?id=CVE-2010-1612
29 Apr 2010 — The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address. The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, y XML Security Gatew... • http://www-01.ibm.com/support/docview.wss?uid=swg1IC61364 •