CVE-2015-7412 Information

Description

The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1 when the GatewayScript decryption API or a JWE decrypt action is enabled do not require signed ciphertext data which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg1IT10701 http://www-01.ibm.com/support/docview.wss?uid=swg21964170

Share on: