The DataPower Gateway must not use 0.0.0.0 as the management IP address.

From IBM DataPower Network Device Management Security Technical Implementation Guide

Part of SRG-APP-000038-NDM-000213

Associated with: CCI-001368

SV-79679r1_rule The DataPower Gateway must not use 0.0.0.0 as the management IP address.

Vulnerability discussion

If 0.0.0.0 as the management IP address, the DataPower appliance will listen on all configured interfaces for management traffic. This can allow an attacker to gain privileged-level access from an untrusted network.

Check content

Using an administrator account, log on to the default domain of the appliance. Navigate to Network >> Management >> Web Management Service. View the Local Address field; if the value is “0.0.0.0”, this is a finding.

Fix text

To configure the DataPower appliance for web management: Using an administrator account, log on to the default domain of the appliance. On the Configure Web Management Service screen, complete the required information. Set the Administrative state to “enabled”. For the Local Address, use the IP address from the management subnet assigned to the unit.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer