Security Bulletin: IBM DataPower Gateway does not force a Gateway Peering password change

Vulnerability Details

Basic Information

Title Security Bulletin: IBM DataPower Gateway does not force a Gateway Peering password change
Type ibm
Published 2025-04-29T02:23:51
Last Seen 2025-04-29T11:06:02
CVSS Score 8.8 (HIGH)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity LOW
Privileges Required LOW
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2022-31776
CWE
Bulletin Family software

Description

## Summary

The DataPower UI does not notify customers of any gateway-peering instance that uses the system default password. The UI will now warn if the password is not changed.

## Vulnerability Details

**CVEID:**CVE-2022-31776
**DESCRIPTION:** IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 228433.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/228433 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

## Affected Products and Versions

Affected Product(s) | Version(s)
—|—
IBM DataPower Gateway 10.5.0 | 10.5.0.0
IBM DataPower Gateway V10CD | 10.0.2.0 – 10.0.4.0
IBM DataPower Gateway 10.0.1 | 10.0.1.0 – 10.0.1.8
IBM DataPower Gateway | 2018.4.1.0 – 2018.4.1.21

## Remediation/Fixes

Affected Product | Fixed in version | APAR
—|—|—
IBM DataPower Gateway 10.5.0.0 | 10.5.0.1 | IT41462
IBM DataPower Gateway V10CD | 10.5.0.1 | IT41462
IBM DataPower Gateway 10.0.1 | 10.5.0.1 | IT41462
IBM DataPOwer Gateway 2018.4.1 | 10.5.0.1 | IT41462

Customers using IBM DataPower Gateway 10.0.1 or 2108.4.1 may obtain the fix by upgrading to version 10.5.0.1; The fix will be available in a future fixpack on those releases.

## Workarounds and Mitigations

None

##

Impact Assessment

Base Score 8.8
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.