First published: Fri Jan 11 2019(Updated: )
IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | >=7.5.0.0<=7.5.0.19 | |
IBM DataPower Gateway | >=7.5.1.0<=7.5.1.18 | |
IBM DataPower Gateway | >=7.5.2.0<=7.5.2.18 | |
IBM DataPower Gateway | >=7.6.0.0<=7.6.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1668 is high.
Versions 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 of IBM DataPower Gateway are affected by CVE-2018-1668.
CVE-2018-1668 is a vulnerability in IBM DataPower Gateway appliances that allows 'null' logins, potentially giving read access to IPMI data and obtaining sensitive information.
An attacker can exploit CVE-2018-1668 by using 'null' logins to gain unauthorized read access to IPMI data on IBM DataPower Gateway appliances.
Yes, IBM has provided fixes and patches for CVE-2018-1668. Please refer to the IBM Support website for more information.