CVE-2018-1665: Weak Encryption
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144891.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for IBM DataPower Gateway?
The vulnerability ID for IBM DataPower Gateway is CVE-2018-1665.
What is the severity of CVE-2018-1665?
The severity of CVE-2018-1665 is high.
What is the affected software for CVE-2018-1665?
The affected software for CVE-2018-1665 is IBM DataPower Gateway versions 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3.
What is the description of CVE-2018-1665?
CVE-2018-1665 is a vulnerability in IBM DataPower Gateway that allows an attacker to decrypt highly sensitive information due to the use of weaker than expected cryptographic algorithms.
How can I fix CVE-2018-1665?
To fix CVE-2018-1665, update IBM DataPower Gateway to a version that does not use weaker cryptographic algorithms.