DataPower

DataPower

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Is Datapower vulnerable to CVE-2024-1086?

    Posted Thu June 06, 2024 06:12 AM

    Hey folks,

    Is Datapower vulnerable to CVE-2024-1086?  Is there a firmware update that mitigates it?   I'm running IDG.10.5.0.11

    Thanks!



    ------------------------------
    John Parker
    ------------------------------


  • 2.  RE: Is Datapower vulnerable to CVE-2024-1086?

    Posted Fri June 07, 2024 12:18 AM

    @Ulas Cubuk: Can you clarify on this?



    ------------------------------
    Ajitabh Sharma
    ------------------------------



  • 3.  RE: Is Datapower vulnerable to CVE-2024-1086?

    Posted Sun June 09, 2024 01:03 AM

    My understanding is that CVE-2024-1086 is a Linux kernel vulnerability. I don't understand how DataPower would be exposed to that. 



    ------------------------------
    Jim T.
    ------------------------------



  • 4.  RE: Is Datapower vulnerable to CVE-2024-1086?

    Posted Mon June 10, 2024 06:08 AM

    I think that Datapower uses a stripped down version of Linux.



    ------------------------------
    John Parker
    ------------------------------



  • 5.  RE: Is Datapower vulnerable to CVE-2024-1086?

    Posted Mon June 10, 2024 10:52 AM

    Yes.  DataPower is somewhat based on Linux, especially WRT commands.   However, the underlying Kernel likely uses quite a bit more, the extent of which only the IBM folks will know.

    We'll have to wait for them, and, as we all know, IBM won't announce it if DataPower is vulnerable until they have a firmware available for us to upgrade.



    ------------------------------
    Joseph Morgan
    ------------------------------



  • 6.  RE: Is Datapower vulnerable to CVE-2024-1086?

    Posted Fri June 28, 2024 05:27 PM

    Now that 10.5.0.12 shipped today
    https://www.ibm.com/support/pages/fix-packs-datapower-gateway-1050x

    10.5.0.12 and 10.6.0.0 contain many CVE fixes, including CVE-2024-1086, which is handled by this APAR:
    (UPDATE KERNEL TO ADDRESS MULTIPLE CVES)
    https://www.ibm.com/support/pages/apar/IT46276



    ------------------------------
    Hermann Stamm-Wilbrandt
    Compiler Level 3 support, IBM DataPower Gateways
    IBM
    Boeblingen
    ------------------------------