CVE-2018-1388: Infoleak
Published Feb 7, 2018
·Updated
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.
Affected Software
15 affected components
IBM WebSphere MQ=7.0.1.0
IBM WebSphere MQ=7.0.1.1
IBM WebSphere MQ=7.0.1.2
IBM WebSphere MQ=7.0.1.3
IBM WebSphere MQ=7.0.1.4
IBM WebSphere MQ=7.0.1.5
IBM WebSphere MQ=7.0.1.6
IBM WebSphere MQ=7.0.1.7
IBM WebSphere MQ=7.0.1.8
IBM WebSphere MQ=7.0.1.9
IBM WebSphere MQ=7.0.1.10
IBM WebSphere MQ=7.0.1.11
IBM WebSphere MQ=7.0.1.12
IBM WebSphere MQ=7.0.1.13
IBM WebSphere MQ=7.0.1.14
Event History
Feb 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1388.
2
What is the severity of CVE-2018-1388?
The severity of CVE-2018-1388 is high with a severity value of 7.5.
3
What software is affected by CVE-2018-1388?
IBM WebSphere MQ versions 7.0.1.0 to 7.0.1.14 are affected by CVE-2018-1388.
4
How can an attacker exploit CVE-2018-1388?
An attacker can exploit CVE-2018-1388 by using side channel information to identify valid and invalid PKCS#1 padding.
5
How can I mitigate CVE-2018-1388?
To mitigate CVE-2018-1388, it is recommended to apply the security patches provided by IBM.