IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Datapower_gateway | Ibm | 7.1.0.0 (including) | 7.1.0.20 (including) |
Datapower_gateway | Ibm | 7.2.0.0 (including) | 7.2.0.17 (including) |
Datapower_gateway | Ibm | 7.5.0.0 (including) | 7.5.0.11 (including) |
Datapower_gateway | Ibm | 7.5.1.0 (including) | 7.5.1.10 (including) |
Datapower_gateway | Ibm | 7.5.2.0 (including) | 7.5.2.10 (including) |
Datapower_gateway | Ibm | 7.6.0.0 (including) | 7.6.0.3 (including) |