Impact
IBM DataPower Gateway can be remotely triggered to exhaust system resources, causing a denial of service. The flaw is rooted in improper resource limitations and falls under CWE‑770; it impacts availability but does not directly compromise confidentiality or integrity.
Affected Systems
Vulnerable IBM DataPower Gateway firmware includes versions 10.5.0, 10.6.0, 10.6CD, and 11.0.0. The issue applies to all releases in these product lines listed above.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity. The EPSS score of 0.00313 indicates a low exploitation probability, and the vulnerability is not currently flagged in CISA KEV. An attacker can remotely exploit the flaw over HTTP/2 traffic, leading to a service outage unless mitigated.
OpenCVE Enrichment