IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.
The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Datapower_gateway | Ibm | 7.6.0.0 (including) | 7.6.0.14 (including) |
| Datapower_gateway | Ibm | 2018.4.1.0 (including) | 2018.4.1.5 (including) |