#VU16642 Denial of service in IBM DataPower Gateway - CVE-2018-1652

 

#VU16642 Denial of service in IBM DataPower Gateway - CVE-2018-1652

Published: December 11, 2018 / Updated: December 20, 2018


Vulnerability identifier: #VU16642
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-1652
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
IBM DataPower Gateway
Software vendor:
IBM Corporation

Description

The vulnerability allows a local unprivileged attacker to cause DoS condition.

The vulnerability exists due to unspecified flaw. A local attacker can cause the service to crash.


Remediation

Install update from vendor's website:
IBM DataPower Gateway 7.1.0.20 IT21445 Install the fix pack.
IBM DataPower Gateway 7.2.0.17 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.0.11 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.1.10 IT21445 Install the fix pack.
IBM DataPower Gateway 7.5.2.10 IT21445 Install the fix pack.
IBM DataPower Gateway 7.6.0.3 IT21445 Install the fix pack.

External links