Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-10-08
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Cross‑site scripting leading to credential disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM DataPower Gateway is vulnerable to a cross‑site scripting flaw that allows an authenticated user to inject arbitrary JavaScript into the Web UI. The weakness is a classic CWE‑79 vulnerability; injected scripts can alter page behavior, capture session cookies, or otherwise exfiltrate credentials stored in a trusted session, potentially leading to credential theft or session hijacking.

Affected Systems

Affected products include IBM DataPower Gateway versions 10.5.0, 10.6.0, 10.6CD, and 11.0.0. The vulnerability spans multiple minor releases: 10.5.0.0–10.5.0.22, 10.6.0.0–10.6.0.10, 10.6.1–10.6.6, and 11.0.0.0–11.0.0.2. IBM has released patched versions in the 10.5.0.23 and later releases, in the 10.6.0.11 and later releases, in the 10.6CD 10.6.6 and later releases, and in the 11.0.0.3 and later releases.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, meaning no confirmed exploitation reports yet. However, the flaw requires an authenticated session and access to the Web UI, limiting the attack surface to users with valid credentials. Once logged in, an attacker can inject scripts that execute in the context of the trusted session, potentially capturing credentials or other sensitive data.

Generated by OpenCVE AI on October 8, 2026 at 16:16 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade IBM DataPower Gateway to the latest fixed release—such as 10.5.0.23 or newer, 10.6.0.11 or newer, 10.6CD 10.6.6 or newer, or 11.0.0.3 or newer—
  • If an upgrade is not immediately possible, restrict Web UI access to only essential administrators, disable or block JavaScript injection in the UI settings, and monitor for suspicious script activity.
  • Implement content security policy headers on the Web UI or deploy a web application firewall to detect and block injected scripts as an additional mitigation layer.

Generated by OpenCVE AI on October 8, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM DataPower Gateway Cross-Site Scripting
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:08:07.783Z

Reserved: 2026-06-24T20:39:29.230Z

Link: CVE-2026-13258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:48.393

Modified: 2026-10-08T15:17:48.393

Link: CVE-2026-13258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')