CVE-2018-1666: IBM Datapower Gateway

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

Affected products

  • IBM Datapower Gateway: from 7.5.0.0, up to and including 7.5.0.19; from 7.5.1.0, up to and including 7.5.1.18; from 7.5.2.0, up to and including 7.5.2.18; from 7.6.0.0, up to and including 7.6.0.11; from 7.7.0.0, up to and including 7.7.1.3; version 2018.4.1.0 only

Published 2019-02-07. Last modified 2026-06-17.