Input validation error in IBM DataPower Gateway - CVE-2018-1677

 

Input validation error in IBM DataPower Gateway - CVE-2018-1677

Published: December 20, 2018


Vulnerability identifier: #VU16638
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-1677
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: IBM Corporation
Affected software:
IBM DataPower Gateway

Detailed vulnerability description

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of full file system. A local attacker can cause a denial of service.


How to mitigate CVE-2018-1677

Install updates from vendor's website:
IBM DataPower Gateway  7.1.0.23  IT25469  Install the fix pack.
IBM DataPower Gateway 7.2.0.21 IT25469 Install the fix pack.
IBM DataPower Gateway 7.5.0.16 IT25469 Install the fix pack.
IBM DataPower Gateway 7.5.1.15 IT25469 Install the fix pack.
IBM DataPower Gateway 7.5.2.15 IT25469 Install the fix pack.
IBM DataPower Gateway 7.6.0.8 IT25469 Install the fix pack.
IBM DataPower Gateway 7.7.1.1 IT25469 Install the fix pack.

Sources