CVE-2018-1664IBM Datapower Gateway vulnerability

4 documents4 sources
Severity
7.8HIGHNVD
CNA6.2
EPSS
0.0%
top 87.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 13

Description

IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. IBM X-Force ID: 144890.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDibm/datapower_gateway7.1.0.07.1.0.23+6
CVEListV5ibm/datapower_gateways12 versions+11
CVEListV5ibm/datapower_gateway_cd7.7.0.0, 7.7.1.2+1

🔴Vulnerability Details

2
GHSA
GHSA-vqrm-r3ff-fhp8: IBM DataPower Gateway 72022-05-13
CVEList
CVE-2018-1664: IBM DataPower Gateway 72018-09-25
CVE-2018-1664 — IBM Datapower Gateway vulnerability | cvebase