CVE-2022-22326: IBM Datapower Gateway

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.

Affected products

  • IBM Datapower Gateway: from 10.0.1.0, before 10.0.1.6 (fixed in 10.0.1.6); from 10.0.2.0, before 10.0.5.0 (fixed in 10.0.5.0); from 2018.4.1.0, before 2018.4.1.19 (fixed in 2018.4.1.19)
  • IBM Mq Appliance m2001 Firmware: before 9.2.0.5 (fixed in 9.2.0.5); before 9.2.5 (fixed in 9.2.5)
  • IBM Mq Appliance m2002 Firmware: before 9.2.0.5 (fixed in 9.2.0.5); before 9.2.5 (fixed in 9.2.5)

Published 2022-08-01. Last modified 2026-06-17.