PT-2015-7550 · Ibm · Ibm Datapower Gateway
Published
2015-11-08
·
Updated
2015-11-09
·
CVE-2015-7412
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DataPower Gateways versions 7.2.0.x before 7.2.0.1
Description
The issue allows remote attackers to obtain plaintext data via a padding-oracle attack when the GatewayScript decryption API or a JWE decrypt action is enabled, as the GatewayScript modules do not require signed ciphertext data.
Recommendations
For versions 7.2.0.x before 7.2.0.1, update to version 7.2.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the GatewayScript decryption API or JWE decrypt action until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Datapower Gateway