CVE-2018-1666
Summary
| CVE | CVE-2018-1666 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-07 15:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Datapower Gateway | 2018.4.1.0 | All | All | All |
| Application | Ibm | Datapower Gateway | 2018.4.1.0 | All | All | All |
| Application | Ibm | Datapower Gateway | All | All | All | All |
| Application | Ibm | Datapower Gateway | All | All | All | All |
| Application | Ibm | Datapower Gateway | All | All | All | All |
| Application | Ibm | Datapower Gateway | All | All | All | All |
| Application | Ibm | Datapower Gateway | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| Security Bulletin: IBM DataPower Gateway is affected by a message injection vulnerability (CVE-2018-1666) | CONFIRM | www.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.