Impact
This vulnerability allows an authenticated user to forge signature requests because the system does not properly verify the authenticity of signature data. The flaw stems from insufficient handling of authentication data, which is captured by CWE-345. An attacker who gains legitimate login credentials can generate or modify signature requests that the gateway will accept as valid, potentially leading to unauthorized operations such as data manipulation or policy changes. The impact is primarily a compromise of integrity for accounts with authenticated access, but it does not grant arbitrary code execution or disclosure of sensitive data beyond the forged transactions.
Affected Systems
Affected products include IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. Fixed versions are 10.6CD 10.6.1, 10.6.1 through 10.6.611.0.3, 10.6.0.0 through 10.6.0.1010.6.0.11, 11.0.0.0 through 11.0.0.211.0.0.3, and 10.5.0.0 through 10.5.0.2210.5.0.23.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is classified as medium severity. No EPSS score is available, so the probability of exploitation remains uncertain, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access, it is not publicly exploitable by unauthenticated users; however, if an account is compromised, the attacker can forge signatures directly within the gateway. The risk is mitigated by the authentication requirement, but any credential breach could lead to integrity violations of the system’s operations.
OpenCVE Enrichment