Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Application Gateway
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28787 1 Ibm 2 Application Gateway, Security Verify Access 2025-08-14 N/A 8.7 HIGH
IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.
CVE-2024-45655 1 Ibm 1 Application Gateway 2025-08-12 N/A 5.5 MEDIUM
IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
CVE-2022-22387 1 Ibm 1 Application Gateway 2025-05-20 N/A 5.4 MEDIUM
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965.
CVE-2021-20576 1 Ibm 2 Application Gateway, Security Verify Access 2024-11-21 5.0 MEDIUM 7.5 HIGH
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
CVE-2021-20575 1 Ibm 2 Application Gateway, Security Verify Access 2024-11-21 2.1 LOW 3.3 LOW
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.