CVE-2015-1970: IBM WebSphere Datapower XC10 Appliance Firmware

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.

Affected products

  • IBM WebSphere Datapower XC10 Appliance Firmware: version 2.1.0.0 only; version 2.1.0.1 only; version 2.1.0.2 only; version 2.1.0.3 only; version 2.5.0.0 only; version 2.5.0.1 only; …

Published 2015-08-03. Last modified 2026-06-17.