Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Datapower Gateway
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-7427 1 Ibm 1 Datapower Gateway 2015-11-16 5.0 MEDIUM N/A
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
CVE-2015-7412 1 Ibm 1 Datapower Gateway 2015-11-09 2.6 LOW N/A
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.