First published: Mon Dec 10 2018(Updated: )
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=7.1.0.0<=7.1.0.19 | |
IBM DataPower Gateway | >=7.2.0.0<=7.2.0.16 | |
IBM DataPower Gateway | >=7.5.0.0<=7.5.0.10 | |
IBM DataPower Gateway | >=7.5.1.0<=7.5.1.9 | |
IBM DataPower Gateway | >=7.5.2.0<=7.5.2.9 | |
IBM DataPower Gateway | >=7.6.0.0<=7.6.0.2 | |
IBM MQ Appliance | >=8.0.0.0<=8.0.0.8 | |
IBM MQ Appliance | >=9.0.1<=9.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM DataPower Gateway vulnerability is CVE-2018-1652.
The severity level of CVE-2018-1652 is medium with a CVSS score of 5.5.
The versions of IBM DataPower Gateway affected by CVE-2018-1652 are 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2.
The versions of IBM MQ Appliance affected by CVE-2018-1652 are 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5.
A local user can exploit CVE-2018-1652 to cause a denial of service.