CVE-2018-1668: IBM Datapower Gateway

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.

Affected products

  • IBM Datapower Gateway: from 7.5.0.0, up to and including 7.5.0.19; from 7.5.1.0, up to and including 7.5.1.18; from 7.5.2.0, up to and including 7.5.2.18; from 7.6.0.0, up to and including 7.6.0.11

Published 2019-01-29. Last modified 2026-06-17.