Skip to content
Busque para obtener información sobre los productos y soluciones de InterSystems, las oportunidades de carrera y más.

Alert: CSP Gateway Can Forward Response to Incorrect Web Client

February 11, 2020 – Alert: CSP Gateway Can Forward Response to Incorrect Web Client

*** Updated 2/11/20 2:15pm ***

*** 2017.2.1 version is NOT affected by this defect ***

InterSystems has corrected a defect that can cause the CSP Gateway to forward a response to the wrong web client. This defect is not present in the Web Gateway.

The CSP Gateway is distributed as a component of a full instance installation and also as a standalone installer. Both distributions are affected by the defect. The CSP Gateway installed with the private Apache web server for the Management Portal is also vulnerable. The affected versions of the CSP Gateway are associated with Caché or Ensemble:

  • 2016.1.4 and older
  • 2016.2.0, 2016.2.1, and 2016.2.2
  • 2017.1.0, 2017.1.1, and 2017.1.2
  • 2017.2.0
  • Versions of the CSP Gateway that are included with all HealthShare products based on the above Caché/Ensemble versions

The defect is dependent on the CSP Gateway version and independent of the Caché or Ensemble version that the CSP Gateway connects to.

The correction for this defect is identified as CMT1608. InterSystems recommends upgrading all affected CSP Gateway installations to the latest version of the CSP Gateway (2018.1.3), which is available via the Worldwide Response Center’s software distribution page, in the ‘ Components’ section. Supported customers can request access to the WRC application by contacting the Worldwide Response Center.

If you have any questions regarding this alert, please contact the Worldwide Response Center.

RELATED TOPICS

Latest Alerts & Advisories

Apr 17, 2025
InterSystems has addressed security vulnerabilities that impact applications using OAuth2 Client configurations on InterSystems IRIS, InterSystems IRIS for Health, HealthShare, HealthShare HealthConnect, TrakCare, Caché, and Ensemble. Remediation steps and additional guidance documentation are available from the InterSystems Worldwide Response Center (WRC).
Apr 02, 2025
Product & Versions Affected Explicit Requirements DP-439207 InterSystems IRIS® data platform 2024.3 (AIX) AIX installations Using JSON processing and Unicode non-Latin-1 character sets DP-439280 InterSystems IRIS 2024.3 (containers with IntegratedML) IntegratedML Containers using TensorFlow
Mar 04, 2025
This problem affects the following products:
Mar 04, 2025
This problem affects the following products: