Denial of service in IBM DataPower Gateway - CVE-2018-1652

 

Denial of service in IBM DataPower Gateway - CVE-2018-1652

Published: December 11, 2018 / Updated: December 20, 2018


Vulnerability identifier: #VU16642
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-1652
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: IBM Corporation
Affected software:
IBM DataPower Gateway

Detailed vulnerability description

The vulnerability allows a local unprivileged attacker to cause DoS condition.

The vulnerability exists due to unspecified flaw. A local attacker can cause the service to crash.


How to mitigate CVE-2018-1652

Install update from vendor's website:
IBM DataPower Gateway 7.1.0.20 IT21445 Install the fix pack.
IBM DataPower Gateway 7.2.0.17 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.0.11 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.1.10 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.2.10 IT21445 Install the fix pack.
IBM DataPower Gateway 7.6.0.3 IT21445 Install the fix pack.

Sources