CVE-2018-1652
published 2018-12-11CVE-2018-1652: IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and…
PriorityP418medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.37%
29.3th percentile
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | datapower_gateway | 7.1.0.0 – 7.1.0.19 | — |
| ibm | datapower_gateway | 7.2.0.0 – 7.2.0.16 | — |
| ibm | datapower_gateway | 7.5.0.0 – 7.5.0.10 | — |
| ibm | datapower_gateway | 7.5.1.0 – 7.5.1.9 | — |
| ibm | datapower_gateway | 7.5.2.0 – 7.5.2.9 | — |
| ibm | datapower_gateway | 7.6.0.0 – 7.6.0.2 | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | datapower_gateways | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | — | — |
| ibm | mq_appliance | 8.0.0.0 – 8.0.0.8 | — |
| ibm | mq_appliance | 9.0.1 – 9.0.5 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3rxq-7p39-5hg9: IBM DataPower Gateway 7
ghsa_unreviewed·2022-05-13
CVE-2018-1652 [MEDIUM] CWE-20 GHSA-3rxq-7p39-5hg9: IBM DataPower Gateway 7
IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.
CISA
Paessler PRTG Network Monitor Local File Inclusion Vulnerability
cisa·2025-02-04·CVSS 9.8
CVE-2018-19410 [CRITICAL] Paessler PRTG Network Monitor Local File Inclusion Vulnerability
Vulnerability: Paessler PRTG Network Monitor Local File Inclusion Vulnerability
Affected: Paessler PRTG Network Monitor
Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.paessler.com/prtg/history/prtg-18#18.2.41.1652 ; https://nvd.nist.gov/vuln/detail/CVE-2018-19410
Remediation Due Date: 2025-02-25
No detection rules found.
No writeups or analysis indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/144724https://www.ibm.com/support/docview.wss?uid=ibm10717483https://www.ibm.com/support/docview.wss?uid=ibm10744557https://exchange.xforce.ibmcloud.com/vulnerabilities/144724https://www.ibm.com/support/docview.wss?uid=ibm10717483https://www.ibm.com/support/docview.wss?uid=ibm10744557
2018-12-11
Published