ID

VAR-201801-1028


CVE

CVE-2017-1773


TITLE

IBM DataPower Gateway Vulnerabilities related to insufficient validation of data reliability

Trust: 0.8

sources: JVNDB: JVNDB-2018-001717

DESCRIPTION

IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817. IBM DataPower Gateway Contains vulnerabilities related to insufficient validation of data reliability. Vendors have confirmed this vulnerability IBM X-Force ID: 136817 It is released as.Information may be tampered with. IBM DataPower Gateways is a set of security and integration platforms designed for mobile, cloud, application programming interface (API), network, service-oriented architecture (SOA), B2B and cloud workloads from IBM Corporation of the United States, which can utilize dedicated gateways The platform secures, integrates and optimizes access across channels. A security vulnerability exists in IBM DataPower Gateways. The following versions are affected: IBM DataPower Gateways version 7.1, version 7,2, version 7.5, version 7.6

Trust: 1.8

sources: NVD: CVE-2017-1773 // JVNDB: JVNDB-2018-001717 // VULHUB: VHN-108781 // VULMON: CVE-2017-1773

AFFECTED PRODUCTS

vendor:ibmmodel:datapower gatewayscope:gteversion:7.2.0.0

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:gteversion:7.5.2.0

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:lteversion:7.5.1.10

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:lteversion:7.5.2.10

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:lteversion:7.1.0.20

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:lteversion:7.2.0.17

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:gteversion:7.1.0.0

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:gteversion:7.6.0.0

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:lteversion:7.5.0.11

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:gteversion:7.5.1.0

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:lteversion:7.6.0.3

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:gteversion:7.5.0.0

Trust: 1.0

vendor:ibmmodel:datapower gatewayscope:eqversion:7.1

Trust: 0.8

vendor:ibmmodel:datapower gatewayscope:eqversion:7.2

Trust: 0.8

vendor:ibmmodel:datapower gatewayscope:eqversion:7.5

Trust: 0.8

vendor:ibmmodel:datapower gatewayscope:eqversion:7.6

Trust: 0.8

vendor:ibmmodel:datapower gatewayscope:eqversion:7.2.0.0

Trust: 0.6

sources: JVNDB: JVNDB-2018-001717 // CNNVD: CNNVD-201801-1133 // NVD: CVE-2017-1773

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-1773
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-1773
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201801-1133
value: MEDIUM

Trust: 0.6

VULHUB: VHN-108781
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-1773
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-1773
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-108781
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-1773
baseSeverity: MEDIUM
baseScore: 4.0
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-108781 // VULMON: CVE-2017-1773 // JVNDB: JVNDB-2018-001717 // CNNVD: CNNVD-201801-1133 // NVD: CVE-2017-1773

PROBLEMTYPE DATA

problemtype:CWE-345

Trust: 1.9

sources: VULHUB: VHN-108781 // JVNDB: JVNDB-2018-001717 // NVD: CVE-2017-1773

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201801-1133

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201801-1133

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-001717

PATCH

title:2012758url:http://www-01.ibm.com/support/docview.wss?uid=swg22012758

Trust: 0.8

title:IBM DataPower Gateways Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=78194

Trust: 0.6

sources: JVNDB: JVNDB-2018-001717 // CNNVD: CNNVD-201801-1133

EXTERNAL IDS

db:NVDid:CVE-2017-1773

Trust: 2.6

db:JVNDBid:JVNDB-2018-001717

Trust: 0.8

db:CNNVDid:CNNVD-201801-1133

Trust: 0.7

db:VULHUBid:VHN-108781

Trust: 0.1

db:VULMONid:CVE-2017-1773

Trust: 0.1

sources: VULHUB: VHN-108781 // VULMON: CVE-2017-1773 // JVNDB: JVNDB-2018-001717 // CNNVD: CNNVD-201801-1133 // NVD: CVE-2017-1773

REFERENCES

url:http://www.ibm.com/support/docview.wss?uid=swg22012758

Trust: 1.8

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/136817

Trust: 1.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-1773

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-1773

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/345.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-108781 // VULMON: CVE-2017-1773 // JVNDB: JVNDB-2018-001717 // CNNVD: CNNVD-201801-1133 // NVD: CVE-2017-1773

SOURCES

db:VULHUBid:VHN-108781
db:VULMONid:CVE-2017-1773
db:JVNDBid:JVNDB-2018-001717
db:CNNVDid:CNNVD-201801-1133
db:NVDid:CVE-2017-1773

LAST UPDATE DATE

2024-11-23T22:00:46.291000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-108781date:2018-02-15T00:00:00
db:VULMONid:CVE-2017-1773date:2018-02-15T00:00:00
db:JVNDBid:JVNDB-2018-001717date:2018-03-02T00:00:00
db:CNNVDid:CNNVD-201801-1133date:2018-02-01T00:00:00
db:NVDid:CVE-2017-1773date:2024-11-21T03:22:20.880

SOURCES RELEASE DATE

db:VULHUBid:VHN-108781date:2018-01-31T00:00:00
db:VULMONid:CVE-2017-1773date:2018-01-31T00:00:00
db:JVNDBid:JVNDB-2018-001717date:2018-03-02T00:00:00
db:CNNVDid:CNNVD-201801-1133date:2018-02-01T00:00:00
db:NVDid:CVE-2017-1773date:2018-01-31T15:29:00.290