Fixes are available
APAR status
Closed as program error.
Error description
DataPower GUI was vulnerable to unwanted actions through malicious websites or emails when the user is authenticated to the DataPower.
Local fix
Problem summary
Fix CVE-2018-1661 CSRF vulnerabilities
Problem conclusion
Fix is available in 7.5.0.19, 7.5.1.18, 7.5.2.18, 7.6.0.11 and 2018.4.1.1 For a list of the latest fix packs available, please see: http://www-01.ibm.com/support/docview.wss?uid=swg21237631
Temporary fix
Comments
APAR Information
APAR number
IT26948
Reported component name
DATAPOWER
Reported component ID
DP1234567
Reported release
750
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2018-11-26
Closed date
2018-11-29
Last modified date
2018-12-05
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
DATAPOWER
Fixed component ID
DP1234567
Applicable component levels
R18X PSY
UP
R750 PSY
UP
R751 PSY
UP
R752 PSY
UP
R760 PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"750","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
11 February 2022