First published: Thu Dec 13 2018(Updated: )
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144891.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=7.5.0.0<=7.5.0.18 | |
IBM DataPower Gateway | >=7.5.1.0<=7.5.1.17 | |
IBM DataPower Gateway | >=7.5.2.0<=7.5.2.17 | |
IBM DataPower Gateway | >=7.6.0.0<=7.6.0.10 | |
IBM DataPower Gateway | >=7.7.0.0<=7.7.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for IBM DataPower Gateway is CVE-2018-1665.
The severity of CVE-2018-1665 is high.
The affected software for CVE-2018-1665 is IBM DataPower Gateway versions 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3.
CVE-2018-1665 is a vulnerability in IBM DataPower Gateway that allows an attacker to decrypt highly sensitive information due to the use of weaker than expected cryptographic algorithms.
To fix CVE-2018-1665, update IBM DataPower Gateway to a version that does not use weaker cryptographic algorithms.