CVE-2018-1664: High severity ibm datapower gateway 10.5.0 vulnerability
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1664?
The severity of CVE-2018-1664 is high with a CVSS score of 7.8.
How do I fix CVE-2018-1664?
To fix CVE-2018-1664, apply the necessary patches provided by IBM for the affected versions of DataPower Gateway.
Which versions of IBM DataPower Gateway are affected by CVE-2018-1664?
IBM DataPower Gateway versions 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, 7.6.0.0 - 7.6.0.8, and IBM DataPower Gateway CD versions 7.7.0.0 - 7.7.1.2 are affected by CVE-2018-1664.
What is the vulnerability description of CVE-2018-1664?
CVE-2018-1664 is a vulnerability in IBM DataPower Gateway that allows the exposure of login credentials in the browser cache through the echoing of AMP management interface authorization headers.
Where can I find more information about CVE-2018-1664?
You can find more information about CVE-2018-1664 in the IBM X-Force Exchange vulnerability database and the IBM support documentation.