IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg22012758 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/136817 | vdb entry vendor advisory |