LOW · 3.3

CVE-2022-22326

IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization chec...

Vulnerability Description

IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.

CVSS Score

3.3

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmDatapower Gateway>= 10.0.1.0, < 10.0.1.6
IbmMq Appliance M2002 Firmware< 9.2.0.5
IbmMq Appliance M2002-
IbmMq Appliance M2001 Firmware< 9.2.0.5
IbmMq Appliance M2001-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22326?

CVE-2022-22326 is a vulnerability with a CVSS score of 3.3 (LOW). IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization chec...

How severe is CVE-2022-22326?

CVE-2022-22326 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22326?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Datapower Gateway, Ibm Mq Appliance M2002 Firmware, Ibm Mq Appliance M2002, Ibm Mq Appliance M2001 Firmware, Ibm Mq Appliance M2001.