Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Signature forging by authenticated users
Action: Immediate Update
AI Analysis

Impact

This vulnerability allows an authenticated user to forge signature requests because the system does not properly verify the authenticity of signature data. The flaw stems from insufficient handling of authentication data, which is captured by CWE-345. An attacker who gains legitimate login credentials can generate or modify signature requests that the gateway will accept as valid, potentially leading to unauthorized operations such as data manipulation or policy changes. The impact is primarily a compromise of integrity for accounts with authenticated access, but it does not grant arbitrary code execution or disclosure of sensitive data beyond the forged transactions.

Affected Systems

Affected products include IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. Fixed versions are 10.6CD 10.6.1, 10.6.1 through 10.6.611.0.3, 10.6.0.0 through 10.6.0.1010.6.0.11, 11.0.0.0 through 11.0.0.211.0.0.3, and 10.5.0.0 through 10.5.0.2210.5.0.23.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability is classified as medium severity. No EPSS score is available, so the probability of exploitation remains uncertain, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access, it is not publicly exploitable by unauthenticated users; however, if an account is compromised, the attacker can forge signatures directly within the gateway. The risk is mitigated by the authentication requirement, but any credential breach could lead to integrity violations of the system’s operations.

Generated by OpenCVE AI on October 8, 2026 at 16:01 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade IBM DataPower Gateway to a version that includes the fix, such as 10.6.1 or newer for the 10.6CD branch and the equivalent releases for 10.5.x, 10.6.0.x, and 11.0.x.
  • If an immediate upgrade is not possible, limit network access to the gateway to trusted sources only and enforce additional authentication checks on signature generation paths.
  • Monitor logs for anomalous or unauthorized signature generation activity and review any forged request attempts as a potential indicator of compromised credentials.

Generated by OpenCVE AI on October 8, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.
Title IBM DataPower Gateway Insufficient Verification of Data Authenticity
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-345
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:08:40.802Z

Reserved: 2026-06-24T20:36:21.020Z

Link: CVE-2026-13257

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:48.143

Modified: 2026-10-08T15:17:48.143

Link: CVE-2026-13257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:04Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity