Lucene search

K
ibmIBM1A35248CBBA17AE981ED0B52B133E7CA1678042C1A9C93C2EC8BED2EF8994420
HistoryAug 16, 2021 - 3:33 p.m.

Security Bulletin: IBM DataPower Gateway vulnerable to a DoS

2021-08-1615:33:37
www.ibm.com
32

0.008 Low

EPSS

Percentile

82.3%

Summary

IBM has addressed the aplicable CVE

Vulnerability Details

CVEID:CVE-2021-23840
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by an integer overflow in CipherUpdate. By sending an overly long argument, an attacker could exploit this vulnerability to cause the application to crash.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196848 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 2018.4.1.0-2018.4.1.16

Remediation/Fixes

Affected Product
| Fixed in Version
| APAR

—|—|—
2018.4.1
| 2018.4.1.17
| IT37298

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm datapower gatewayeq2018.4.1