IBM DataPower Gateways Multiple Security Vulnerabilities
BID:106816
Info
IBM DataPower Gateways Multiple Security Vulnerabilities
| Bugtraq ID: | 106816 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1665 CVE-2018-1667 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2018 12:00AM |
| Updated: | Dec 11 2018 12:00AM |
| Credit: | Srinivasarao Kotipalli & Jeremy Soh. |
| Vulnerable: |
IBM DataPower Gateways 7.7.1.1 IBM DataPower Gateways 7.7.0.9 IBM DataPower Gateways 7.7.0.8 IBM DataPower Gateways 7.7.0.7 IBM DataPower Gateways 7.7.0.6 IBM DataPower Gateways 7.7.0.4 IBM DataPower Gateways 7.7.0.2 IBM DataPower Gateways 7.6.0.8 IBM DataPower Gateways 7.6.0.6 IBM DataPower Gateways 7.6.0.5 IBM DataPower Gateways 7.6.0.1 IBM DataPower Gateways 7.6.0.0 IBM DataPower Gateways 7.5.2.9 IBM DataPower Gateways 7.5.2.8 IBM DataPower Gateways 7.5.2.2 IBM DataPower Gateways 7.5.2.15 IBM DataPower Gateways 7.5.2.13 IBM DataPower Gateways 7.5.2.12 IBM DataPower Gateways 7.5.2.1 IBM DataPower Gateways 7.5.2.0 IBM DataPower Gateways 7.5.1.9 IBM DataPower Gateways 7.5.1.8 IBM DataPower Gateways 7.5.1.4 IBM DataPower Gateways 7.5.1.3 IBM DataPower Gateways 7.5.1.2 IBM DataPower Gateways 7.5.1.15 IBM DataPower Gateways 7.5.1.14 IBM DataPower Gateways 7.5.1.13 IBM DataPower Gateways 7.5.1.12 IBM DataPower Gateways 7.5.1.1 IBM DataPower Gateways 7.5.0.9 IBM DataPower Gateways 7.5.0.5 IBM DataPower Gateways 7.5.0.4 IBM DataPower Gateways 7.5.0.3 IBM DataPower Gateways 7.5.0.2 IBM DataPower Gateways 7.5.0.16 IBM DataPower Gateways 7.5.0.15 IBM DataPower Gateways 7.5.0.14 IBM DataPower Gateways 7.5.0.13 IBM DataPower Gateways 7.5.0.10 IBM DataPower Gateways 7.5.0.1 IBM DataPower Gateways 7.5.0.0 IBM DataPower Gateway 7.7.1.3 IBM DataPower Gateway 7.7.0.0 IBM DataPower Gateway 7.6.0.9 IBM DataPower Gateway 7.6.0.3 IBM DataPower Gateway 7.6.0.10 IBM DataPower Gateway 7.5.2.17 IBM DataPower Gateway 7.5.2.16 IBM DataPower Gateway 7.5.2.10 IBM DataPower Gateway 7.5.1.17 IBM DataPower Gateway 7.5.1.16 IBM DataPower Gateway 7.5.1.10 IBM DataPower Gateway 7.5.1.0 IBM DataPower Gateway 7.5.0.18 IBM DataPower Gateway 7.5.0.17 IBM DataPower Gateway 7.5.0.11 |
| Not Vulnerable: |
IBM DataPower Gateway 7.6.0.11 IBM DataPower Gateway 7.5.2.18 IBM DataPower Gateway 7.5.1.18 IBM DataPower Gateway 7.5.0.19 |
Discussion
IBM DataPower Gateways Multiple Security Vulnerabilities
IBM DataPower Gateways is prone to the following vulnerabilities:
1. A security weakness
2. A cross-site scripting vulnerability.
An attacker may leverage these issues to obtain sensitive information or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks and obtain sensitive information.
IBM DataPower Gateway version 7.7.0.0 through 7.7.1.3, 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17 and 7.5.0.0 through 7.5.0.18 are vulnerable.
IBM DataPower Gateways is prone to the following vulnerabilities:
1. A security weakness
2. A cross-site scripting vulnerability.
An attacker may leverage these issues to obtain sensitive information or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks and obtain sensitive information.
IBM DataPower Gateway version 7.7.0.0 through 7.7.1.3, 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17 and 7.5.0.0 through 7.5.0.18 are vulnerable.
Exploit / POC
IBM DataPower Gateways Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM DataPower Gateways Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM DataPower Gateways Multiple Security Vulnerabilities
References:
References: