Description
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM DataPower Gateway can be remotely triggered to exhaust system resources, causing a denial of service. The flaw is rooted in improper resource limitations and falls under CWE‑770; it impacts availability but does not directly compromise confidentiality or integrity.

Affected Systems

Vulnerable IBM DataPower Gateway firmware includes versions 10.5.0, 10.6.0, 10.6CD, and 11.0.0. The issue applies to all releases in these product lines listed above.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity. The EPSS score of 0.00313 indicates a low exploitation probability, and the vulnerability is not currently flagged in CISA KEV. An attacker can remotely exploit the flaw over HTTP/2 traffic, leading to a service outage unless mitigated.

Generated by OpenCVE AI on August 3, 2026 at 10:37 UTC.

Remediation

Vendor Solution

Affected Product(s)Fixed in ReleaseFix InstructionsIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.2 https://www.ibm.com/docs/en/datapower-gateway/11.0.0?topic=overview-release-notes#relnotes__install__title__1 IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.910.6.0.10 https://www.ibm.com/docs/en/datapower-gateway/10.6.0?topic=overview-release-notes#relnotes__install__title__1 IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.111.0.0.2 https://www.ibm.com/docs/en/datapower-gateway/11.0.0?topic=overview-release-notes#relnotes__install__title__1 IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2110.5.0.22 https://www.ibm.com/docs/en/datapower-gateway/10.5.0?topic=overview-release-notes#relnotes__install__title__1 https://www.ibm.com/docs/en/datapower-gateway/11.0.0 IBM strongly advises upgrading as soon as possible.


Vendor Workaround

Disable HTTP/2.


OpenCVE Recommended Actions

  • Upgrade the IBM DataPower Gateway to a version that includes the fix—10.5.0.2110.5.0.22 or later, 10.6.0.910.6.0.10 or later, 10.6.1‑10.6.611.0.0.2 for 10.6CD, or 11.0.0.111.0.0.2 for 11.0.0. This resolves the insufficient resource‑limitation problem.
  • If an upgrade cannot be applied immediately, disable HTTP/2 in the DataPower configuration to mitigate attack vectors until the patch is available.
  • Add monitoring or rate‑limiting rules for HTTP/2 connections to detect and throttle abnormal traffic patterns, helping to protect the appliance until a formal fix is.

Generated by OpenCVE AI on August 3, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
Title IBM DataPower Gateway affected by denial of service
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-770
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Datapower Gateway Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-31T15:59:20.632Z

Reserved: 2026-06-19T16:05:01.990Z

Link: CVE-2026-12733

cve-icon Vulnrichment

Updated: 2026-07-31T15:20:54.380Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:17:04.867

Modified: 2026-08-10T20:08:49.003

Link: CVE-2026-12733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling