Fixes are available
Fix packs for DataPower Gateway version 2018.4, 7.7
Fix packs for DataPower Gateway version 7.1
Fix packs for DataPower Gateway version 7.2
Fix packs for DataPower Gateway version 7.5
Fix packs for DataPower Gateway version 7.5.1
Fix packs for DataPower Gateway version 7.5.2
Fix packs for DataPower Gateway version 7.6
APAR status
Closed as program error.
Error description
Sensitive information disclosure in DataPower management interface DETAILS The DataPower management interface may echo client-provided authentication information in response headers.
Local fix
Problem summary
Fix CVE-2018-1664 as it pertains to the AMP interface returning login credentials.
Problem conclusion
The fix will be in 7.1.0.24, 7.2.0.22, 7.5.0.17, 7.5.1.16, 7.5.2.16, 7.6.0.9, 7.7.1.3
Temporary fix
Comments
APAR Information
APAR number
IT26030
Reported component name
DATAPOWER
Reported component ID
DP1234567
Reported release
770
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2018-09-05
Closed date
2018-09-05
Last modified date
2018-09-05
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
DATAPOWER
Fixed component ID
DP1234567
Applicable component levels
R710 PSY
UP
R720 PSY
UP
R750 PSY
UP
R751 PSY
UP
R752 PSY
UP
R760 PSY
UP
R770 PSY
UP
[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateways"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"770"}]
Document Information
Modified date:
27 September 2021