PT-2018-13671 · Ibm · Ibm Datapower Gateway

Jeremy Soh

+1

·

Published

2018-12-13

·

Updated

2019-10-09

·

CVE-2018-1665

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM DataPower Gateway versions 7.5.0.0 through 7.5.0.18 IBM DataPower Gateway versions 7.5.1.0 through 7.5.1.17 IBM DataPower Gateway versions 7.5.2.0 through 7.5.2.17 IBM DataPower Gateway versions 7.6.0.0 through 7.6.0.10 IBM DataPower Gateway versions 7.7.0.0 through 7.7.1.3
Description The issue is related to the use of weaker than expected cryptographic algorithms, which could allow an attacker to decrypt highly sensitive information.
Recommendations For IBM DataPower Gateway versions 7.5.0.0 through 7.5.0.18, update to a version that uses stronger cryptographic algorithms. For IBM DataPower Gateway versions 7.5.1.0 through 7.5.1.17, update to a version that uses stronger cryptographic algorithms. For IBM DataPower Gateway versions 7.5.2.0 through 7.5.2.17, update to a version that uses stronger cryptographic algorithms. For IBM DataPower Gateway versions 7.6.0.0 through 7.6.0.10, update to a version that uses stronger cryptographic algorithms. For IBM DataPower Gateway versions 7.7.0.0 through 7.7.1.3, update to a version that uses stronger cryptographic algorithms.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1665

Affected Products

Ibm Datapower Gateway