Lucene search

K
ibmIBM1F234EFC9BCA33D00375D73A19EA38D309527628B71CCB02CAF517D9F70083C2
HistoryJun 08, 2021 - 9:52 p.m.

Security Bulletin: Vulnerabities in SSL in IBM DataPower Gateway

2021-06-0821:52:38
www.ibm.com
24
ibm datapower gateway
ssl
vulnerabilities
cve-2019-1559
cve-2018-0734
openssl 1.0.2r
openssl 1.1.1a
security bulletin

EPSS

0.011

Percentile

84.7%

Summary

IBM DataPower Gateway has addressed two CVEs relating to SSL: CVE-2019-1559 & CVE-2018-0734

Vulnerability Details

CVEID:CVE-2019-1559
**DESCRIPTION:**If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable “non-stitched” ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).
CVSS Base score: 5.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/157514 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)

CVEID:CVE-2018-0734
**DESCRIPTION:**The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p).
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/152085 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM DataPower Gateway 2018.4.1.-2018.4.1.8
IBM DataPower Gateway 7.6.0.0-7.6.0.17

Remediation/Fixes

Affected Product Fixed in version APAR
IBM DataPower Gateway 7.6.0.18 IT30948
IBM DataPower Gateway 2018.4.1.9 IT30948

Workarounds and Mitigations

None