Denial of service in IBM DataPower Gateway - CVE-2018-1652

 

Denial of service in IBM DataPower Gateway - CVE-2018-1652

Published: December 11, 2018 / Updated: December 20, 2018


Vulnerability identifier: #VU16642
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1652
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unprivileged attacker to cause DoS condition.

The vulnerability exists due to unspecified flaw. A local attacker can cause the service to crash.


Affected software

IBM DataPower Gateway

How to mitigate CVE-2018-1652

Install update from vendor's website:
IBM DataPower Gateway 7.1.0.20 IT21445 Install the fix pack.
IBM DataPower Gateway 7.2.0.17 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.0.11 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.1.10 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.2.10 IT21445 Install the fix pack.
IBM DataPower Gateway 7.6.0.3 IT21445 Install the fix pack.


External References

Related Security Bulletins