CVE-2024-28787: IBM Application Gateway

Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.

Affected products

  • IBM Application Gateway: from 20.01, up to and including 24.03
  • IBM Security Verify Access: from 10.0.0, up to and including 10.0.7

Published 2024-04-04. Last modified 2026-06-17.