Input validation error in IBM DataPower Gateway - CVE-2018-1677

 

Input validation error in IBM DataPower Gateway - CVE-2018-1677

Published: December 20, 2018


Vulnerability identifier: #VU16638
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1677
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper handling of full file system. A local attacker can cause a denial of service.


Affected software

IBM DataPower Gateway

How to mitigate CVE-2018-1677

Install updates from vendor's website:
IBM DataPower Gateway  7.1.0.23  IT25469  Install the fix pack.
IBM DataPower Gateway 7.2.0.21 IT25469 Install the fix pack.
IBM DataPower Gateway 7.5.0.16 IT25469 Install the fix pack.
IBM DataPower Gateway 7.5.1.15 IT25469 Install the fix pack.
IBM DataPower Gateway 7.5.2.15 IT25469 Install the fix pack.
IBM DataPower Gateway 7.6.0.8 IT25469 Install the fix pack.
IBM DataPower Gateway 7.7.1.1 IT25469 Install the fix pack.


External References

Related Security Bulletins