Impact
The flaw arises from an improper authorization check in IBM DataPower Gateway, enabling an attacker who can access the device locally to read data that should be protected. This vulnerability is categorized as CWE‑863 and directly impacts the confidentiality of any sensitive information routed through or stored on the gateway.
Affected Systems
Affected IBM DataPower Gateway versions are 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known public exploit. The attack requires local‑system access, so the threat is primarily from insiders or attackers that have physical or console access to the gateway device. While the impact is limited to data disclosure without remote code execution or denial of service, the presence of the flaw still warrants timely remediation because it permits bypassing of authorization controls.
OpenCVE Enrichment