Security Bulletin
Summary
IBM has released the following fixpack for IBM DataPower Gateways in response to CVE-2017-5753.
Vulnerability Details
CVEID: CVE-2017-5753
Affected Products and Versions
IBM DataPower Gateways appliances, versions 7.1.0.0-7.1.0.21, 7.2.0.0-7.2.0.18, 7.5.0.0-7.5.0.12, 7.5.1.0-7.5.1.11, 7.5.2.0-7.5.2.11, 7.6.0.0-7.6.0.4
Remediation/Fixes
Fix is available in versions 7.1.0.23, 7.2.0.21, 7.5.0.13, 7.5.1.12, 7.5.2.12, 7.6.0.5. Refer to APAR IT24077 for URLs to download the fix.
You should verify applying this fix does not cause any compatibility issues.
For DataPower customers using versions 7.0.0 and earlier versions, IBM recommends upgrading to a fixed, supported version/release/platform of the product.
Workarounds and Mitigations
Do not use configurations that permit the execution of untrusted policy scripts
Monitor IBM Cloud Status for Future Security Bulletins
Monitor the security notifications on the IBM Cloud Status page to be advised of future security bulletins.
References
Acknowledgement
None
Change History
27 February 2018 Original version published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Internal Use Only
Advisory ID 10685
Product Record ID 106574
Was this topic helpful?
Document Information
Modified date:
08 June 2021
UID
swg22014050