Impact
IBM DataPower Gateway is vulnerable to a cross‑site scripting flaw that allows an authenticated user to inject arbitrary JavaScript into the Web UI. The weakness is a classic CWE‑79 vulnerability; injected scripts can alter page behavior, capture session cookies, or otherwise exfiltrate credentials stored in a trusted session, potentially leading to credential theft or session hijacking.
Affected Systems
Affected products include IBM DataPower Gateway versions 10.5.0, 10.6.0, 10.6CD, and 11.0.0. The vulnerability spans multiple minor releases: 10.5.0.0–10.5.0.22, 10.6.0.0–10.6.0.10, 10.6.1–10.6.6, and 11.0.0.0–11.0.0.2. IBM has released patched versions in the 10.5.0.23 and later releases, in the 10.6.0.11 and later releases, in the 10.6CD 10.6.6 and later releases, and in the 11.0.0.3 and later releases.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, meaning no confirmed exploitation reports yet. However, the flaw requires an authenticated session and access to the Web UI, limiting the attack surface to users with valid credentials. Once logged in, an attacker can inject scripts that execute in the context of the trusted session, potentially capturing credentials or other sensitive data.
OpenCVE Enrichment