Vulnerability Name: | CVE-2018-1665 (CCN-144891) |
Assigned: | 2017-12-13 |
Published: | 2018-12-11 |
Updated: | 2019-10-09 |
Summary: | IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144891.
|
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): None Availibility (A): None | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-326
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2018-1665
Source: CCN Type: IBM Security Bulletin 744195 (DataPower Gateway) IBM DataPower Gateway is affected by a vulnerability (CVE-2018-1665)
Source: CONFIRM Type: Patch, Vendor Advisory http://www.ibm.com/support/docview.wss?uid=ibm10744195
Source: XF Type: UNKNOWN ibm-websphere-cve20181665-info-disc(144891)
Source: XF Type: VDB Entry, Vendor Advisory ibm-websphere-cve20181665-info-disc(144891)
Source: CCN Type: IBM Security Bulletin 739239 (MQ Appliance) IBM MQ Appliance is affected by weak cryptographic algorithms (CVE-2018-1665)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:ibm:datapower_gateway:*:*:*:*:*:*:*:* (Version >= 7.5.0.0 and <= 7.5.0.18)OR cpe:/a:ibm:datapower_gateway:*:*:*:*:*:*:*:* (Version >= 7.5.1.0 and <= 7.5.1.17)OR cpe:/a:ibm:datapower_gateway:*:*:*:*:*:*:*:* (Version >= 7.5.2.0 and <= 7.5.2.17)OR cpe:/a:ibm:datapower_gateway:*:*:*:*:*:*:*:* (Version >= 7.6.0.0 and <= 7.6.0.10)OR cpe:/a:ibm:datapower_gateway:*:*:*:*:*:*:*:* (Version >= 7.7.0.0 and <= 7.7.1.3) Configuration CCN 1: cpe:/a:ibm:datapower_gateway:7.6.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:datapower_gateway:7.5.2.0:*:*:*:*:*:*:*OR cpe:/a:ibm:datapower_gateway:7.5.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:datapower_gateway:7.5.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:datapower_gateway:7.7.0.0:*:*:*:continuous_delivery:*:*:*OR cpe:/a:ibm:datapower_gateway:7.7.1.3:*:*:*:continuous_delivery:*:*:*
Denotes that component is vulnerable |
BACK |