PT-2022-25296 · Ibm · Ibm Datapower Gateway

Published

2022-11-22

·

Updated

2022-11-26

·

CVE-2022-40228

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM DataPower Gateway versions 10.0.1.0 through 10.0.1.9 IBM DataPower Gateway versions 10.0.3.0 through 10.0.4.0 IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.22 IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.2
Description The issue arises because the system does not invalidate session after a password change, which could allow an authenticated user to impersonate another user on the system.
Recommendations For IBM DataPower Gateway versions 10.0.1.0 through 10.0.1.9, update to a version that includes the session invalidation fix after a password change. For IBM DataPower Gateway versions 10.0.3.0 through 10.0.4.0, update to a version that includes the session invalidation fix after a password change. For IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.22, update to a version that includes the session invalidation fix after a password change. For IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.2, update to a version that includes the session invalidation fix after a password change. As a temporary workaround, consider implementing additional authentication checks to minimize the risk of impersonation until a patch is available.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2022-40228

Affected Products

Ibm Datapower Gateway