Vulnerability Details
Basic Information
| Title | Security Bulletin: IBM DataPower Gateway does not force a Gateway Peering password change |
|---|---|
| Type | ibm |
| Published | 2025-04-29T02:23:51 |
| Last Seen | 2025-04-29T11:06:02 |
| CVSS Score | 8.8 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2022-31776 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
The DataPower UI does not notify customers of any gateway-peering instance that uses the system default password. The UI will now warn if the password is not changed.
## Vulnerability Details
**CVEID:**CVE-2022-31776
**DESCRIPTION:** IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 228433.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/228433 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
## Affected Products and Versions
Affected Product(s) | Version(s)
—|—
IBM DataPower Gateway 10.5.0 | 10.5.0.0
IBM DataPower Gateway V10CD | 10.0.2.0 – 10.0.4.0
IBM DataPower Gateway 10.0.1 | 10.0.1.0 – 10.0.1.8
IBM DataPower Gateway | 2018.4.1.0 – 2018.4.1.21
## Remediation/Fixes
Affected Product | Fixed in version | APAR
—|—|—
IBM DataPower Gateway 10.5.0.0 | 10.5.0.1 | IT41462
IBM DataPower Gateway V10CD | 10.5.0.1 | IT41462
IBM DataPower Gateway 10.0.1 | 10.5.0.1 | IT41462
IBM DataPOwer Gateway 2018.4.1 | 10.5.0.1 | IT41462
Customers using IBM DataPower Gateway 10.0.1 or 2108.4.1 may obtain the fix by upgrading to version 10.5.0.1; The fix will be available in a future fixpack on those releases.
## Workarounds and Mitigations
None
##
Impact Assessment
| Base Score | 8.8 |
|---|---|
| Severity | HIGH |