The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.
                
            References
                    | Link | Resource | 
|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg21964170 | Vendor Advisory | 
| http://www-01.ibm.com/support/docview.wss?uid=swg1IT10701 | Vendor Advisory | 
Configurations
                    Information
                Published : 2015-11-08 14:59
Updated : 2015-11-09 12:25
NVD link : CVE-2015-7412
Mitre link : CVE-2015-7412
JSON object : View
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
                ibm
- datapower_gateway
 


