CVE-2018-1667
13.12.2018, 16:29
IBM DataPower Gateway 7.6.0.0 through 7.6.0.10, 7.5.2.0 through 7.5.2.17, 7.5.1.0 through 7.5.1.17, 7.5.0.0 through 7.5.0.18, and 7.7.0.0 through 7.7.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144893.
Vendor | Product | Version |
---|---|---|
ibm | datapower_gateway | 7.5.0.0 ≤ 𝑥 ≤ 7.5.0.18 |
ibm | datapower_gateway | 7.5.1.0 ≤ 𝑥 ≤ 7.5.1.17 |
ibm | datapower_gateway | 7.5.2.0 ≤ 𝑥 ≤ 7.5.2.17 |
ibm | datapower_gateway | 7.6.0.0 ≤ 𝑥 ≤ 7.6.0.10 |
ibm | datapower_gateway | 7.7.0.0 ≤ 𝑥 ≤ 7.7.1.3 |
𝑥
= Vulnerable software versions