First published: Sat Nov 14 2015(Updated: )
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway 10.5.0 | <=6.0.0.16 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.0 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.1 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.2 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.3 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.4 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.5 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.6 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.7 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.8 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.9 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.10 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.11 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.12 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.13 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.14 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.15 | |
IBM DataPower Gateway 10.5.0 | =6.0.1.16 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.0 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.1 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.2 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.3 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.4 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.5 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.6 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.7 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.8 | |
IBM DataPower Gateway 10.5.0 | =7.0.0.9 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.0 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.1 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.2 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.3 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.4 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.5 | |
IBM DataPower Gateway 10.5.0 | =7.1.0.6 | |
IBM DataPower Gateway 10.5.0 | =7.2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7427 is classified as a medium severity vulnerability.
To fix CVE-2015-7427, you should upgrade to firmware version 6.0.0.17 or later, 6.0.1.17 or later, 7.0.0.10 or later, 7.1.0.7 or later, or 7.2.0.1 or later for IBM DataPower Gateway appliances.
CVE-2015-7427 affects IBM DataPower Gateway appliances running firmware versions prior to 6.0.0.17, 6.0.1.17, 7.0.0.10, 7.1.0.7, and 7.2.0.1.
CVE-2015-7427 involves the absence of the secure flag for unspecified cookies in an HTTPS session, making them vulnerable to capture by remote attackers.
Organizations using IBM DataPower Gateway appliances with the specified firmware versions before the recommended updates are impacted by CVE-2015-7427.