DataPower

DataPower

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Data Power is not validating the user inputs fields properly - Improper Input Validation.

  • 1.  Data Power is not validating the user inputs fields properly - Improper Input Validation.

    Posted 4 hours ago

    Dear Team,

    Recently VAPT was performed on IBM Data Power. Below point is the observation raised by Team.

    Is there any solution to fix the above raised point.

    Tool Used : Burp Suite

    The application is not validating the user input fields properly at the server end. As a result, a malicious user may insert malicious scripts into the application and compromise it.



    ------------------------------
    Umesh Chandra
    ------------------------------


  • 2.  RE: Data Power is not validating the user inputs fields properly - Improper Input Validation.

    Posted 26 minutes ago

    The VAPT tool is updating configurations?   Are the configuration access points (GUI/XMI/REST/CLI) exposed to these threats in an unreasonable way (access via public internet or not fire walled to a vault-only controlled access point, etc.).   We could get into an entire encyclopedia of "what ifs" in this world, and, in fact, we could "what if" everything into being compromised.   The question becomes one of, "Are you taking all reasonable and known steps to prevent a threat-actor from changing your configurations."

    For this (and that is after you've taken all reasonable and known steps in preventing threat-actors, internal and otherwise, from changing appliance configurations) you essentially have two choices:

    1. Take it to IBM and have them work on it.
    2. Proxy the management traffic and scan for such things during configuration changes.



    ------------------------------
    Joseph Morgan
    CEO - Independent
    ------------------------------