Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptographic signatures.
Published: 2026-10-08
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Bypassed security restrictions via improper cryptographic signature verification
Action: Patch Now
AI Analysis

Impact

This vulnerability arises when the DataPower Gateway fails to properly verify cryptographic signatures on incoming data. A remote attacker who is authenticated to the gateway can craft messages or configuration changes that appear signed, allowing the system to accept them and thus bypass the intended security controls. The weakness is a classic example of cryptographic validation failure (CWE-347), and while it does not provide remote code execution, it enables serious privilege or configuration escalation within the gateway.

Affected Systems

The flaw affects IBM DataPower Gateway products from version 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. All listed variants of the gateway are potentially impacted unless a patch has been applied.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. Because the EPSS score is not available, the exact likelihood of exploitation is uncertain, but the lack of a KEV listing suggests no confirmed exploits yet. Exploitation requires the attacker to have valid credentials for the gateway, after which the attacker can submit forged signed data. The impact is the potential to override security restrictions or inject configuration changes, which could compromise the confidentiality, integrity, and availability of the protected services.

Generated by OpenCVE AI on October 8, 2026 at 16:05 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade to a fixed version (10.6CD 10.6.1.0 or newer, 10.6.0.0‑10.6.0.11, 11.0.0.0‑11.0.0.21, or newer 10.5.0.0‑10.5.0.22)
  • Verify that cryptographic signature validation is enabled on all security policies after the upgrade
  • Limit remote authenticated access to trusted network segments or privileged users until a patch is applied

Generated by OpenCVE AI on October 8, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptographic signatures.
Title IBM DataPower Gateway Improper Verification of Cryptographic Signature
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-347
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:06:18.996Z

Reserved: 2026-07-02T17:49:52.345Z

Link: CVE-2026-14497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:49.013

Modified: 2026-10-08T15:17:49.013

Link: CVE-2026-14497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature