Security Bulletin: Potential side-channel cryptographic vulnerabilities in IBM DataPower Gateway

IBM DataPower Gateway is potentially vulnerable to two side-channel attacks (CVE-2018-0495, CVE-2018-12404)

Affected product(s) and affected version(s):

Affected Product(s)Version(s)
IBM DataPower Gateway2018.4.1.0-2018.4.1.8
IBM DataPower Gateway7.6.0.0-7.6.0.17

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1167190

The post Security Bulletin: Potential side-channel cryptographic vulnerabilities in IBM DataPower Gateway appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2ZSHrm4