This page lists publicly disclosed CVE vulnerabilities affecting ibm application_gateway (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-36397 | IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | [email protected] | 5.4 | 0.06% | 2026-01-20 | 2026-01-26 |
| CVE-2025-36396 | IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | [email protected] | 5.4 | 0.03% | 2026-01-20 | 2026-01-26 |
| CVE-2024-45655 | IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment. | [email protected] | 5.5 | 0.01% | 2025-06-03 | 2025-08-12 |
| CVE-2024-28787 | IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584. | [email protected] | 8.7 | 0.11% | 2024-04-04 | 2025-08-14 |
| CVE-2022-22387 | IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965. | [email protected] | 5.4 | 0.24% | 2022-09-28 | 2025-05-20 |
| CVE-2021-20576 | IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash. | [email protected] | 7.5 | 1.01% | 2021-06-01 | 2024-11-21 |
| CVE-2021-20575 | IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278. | [email protected] | 3.3 | 0.04% | 2021-06-01 | 2024-11-21 |