CVE-2022-22326

IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:ibm:mq_appliance_m2002_firmware:*:*:*:*:long_term_support:*:*:*
cpe:2.3:o:ibm:mq_appliance_m2002_firmware:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:h:ibm:mq_appliance_m2002:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:ibm:mq_appliance_m2001_firmware:*:*:*:*:long_term_support:*:*:*
cpe:2.3:o:ibm:mq_appliance_m2001_firmware:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:h:ibm:mq_appliance_m2001:-:*:*:*:*:*:*:*

History

04 Aug 2022, 17:36

Type Values Removed Values Added
First Time Ibm mq Appliance M2001 Firmware
Ibm datapower Gateway
Ibm mq Appliance M2001
Ibm mq Appliance M2002 Firmware
Ibm
Ibm mq Appliance M2002
CPE cpe:2.3:h:ibm:mq_appliance_m2001:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:mq_appliance_m2002_firmware:*:*:*:*:long_term_support:*:*:*
cpe:2.3:h:ibm:mq_appliance_m2002:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:mq_appliance_m2001_firmware:*:*:*:*:long_term_support:*:*:*
cpe:2.3:o:ibm:mq_appliance_m2001_firmware:*:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:mq_appliance_m2002_firmware:*:*:*:*:continuous_delivery:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CWE CWE-863
References (CONFIRM) https://www.ibm.com/support/pages/node/6560048 - (CONFIRM) https://www.ibm.com/support/pages/node/6560048 - Patch, Vendor Advisory
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/218856 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/218856 - VDB Entry, Vendor Advisory
References (CONFIRM) https://www.ibm.com/support/pages/node/6608598 - (CONFIRM) https://www.ibm.com/support/pages/node/6608598 - Patch, Vendor Advisory

01 Aug 2022, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-01 11:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-22326

Mitre link : CVE-2022-22326

CVE.ORG link : CVE-2022-22326


JSON object : View

Products Affected

ibm

  • mq_appliance_m2002
  • mq_appliance_m2001
  • mq_appliance_m2001_firmware
  • mq_appliance_m2002_firmware
  • datapower_gateway
CWE
CWE-863

Incorrect Authorization