CVE-2018-1652: Input Validation
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM DataPower Gateway vulnerability?
The vulnerability ID for this IBM DataPower Gateway vulnerability is CVE-2018-1652.
What is the severity level of CVE-2018-1652?
The severity level of CVE-2018-1652 is medium with a CVSS score of 5.5.
Which versions of IBM DataPower Gateway are affected by CVE-2018-1652?
The versions of IBM DataPower Gateway affected by CVE-2018-1652 are 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2.
Which versions of IBM MQ Appliance are affected by CVE-2018-1652?
The versions of IBM MQ Appliance affected by CVE-2018-1652 are 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5.
How can a local user exploit CVE-2018-1652?
A local user can exploit CVE-2018-1652 to cause a denial of service.