CVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to…
Does this matter?
Lower severity and a low EPSS score (1.01%). Track it; it rarely justifies an emergency change on its own.
Description
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 1.01% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/datapower gateway
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT10701Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21964170Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT10701Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21964170Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.