Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM DataPower Gateways GatewayScript模块安全漏洞
Vulnerability Description
IBM DataPower Gateway是美国IBM公司的一套专门为移动、云、应用编程接口(API)、网络、面向服务架构(SOA)、B2B和云工作负载而设计的安全和集成平台,它可利用专用网关平台跨渠道保护、集成和优化访问。GatewayScript是其中的一个用于处理移动、网络和API工作负载以及优化网关环境的模块。 使用7.2.0.0版本软件的IBM DataPower Gateways中的GatewayScript模块存在安全漏洞,该漏洞源于程序使用GatewayScript decryption
CVSS Information
N/A
Vulnerability Type
N/A