CVE Vulnerabilities

CVE-2018-1666

Published: Feb 07, 2019 | Modified: Aug 24, 2020
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

Affected Software

Name Vendor Start Version End Version
Datapower_gateway Ibm 7.5.0.0 (including) 7.5.0.19 (including)
Datapower_gateway Ibm 7.5.1.0 (including) 7.5.1.18 (including)
Datapower_gateway Ibm 7.5.2.0 (including) 7.5.2.18 (including)
Datapower_gateway Ibm 7.6.0.0 (including) 7.6.0.11 (including)
Datapower_gateway Ibm 7.7.0.0 (including) 7.7.1.3 (including)
Datapower_gateway Ibm 2018.4.1.0 (including) 2018.4.1.0 (including)

References