Impact
This vulnerability arises when the DataPower Gateway fails to properly verify cryptographic signatures on incoming data. A remote attacker who is authenticated to the gateway can craft messages or configuration changes that appear signed, allowing the system to accept them and thus bypass the intended security controls. The weakness is a classic example of cryptographic validation failure (CWE-347), and while it does not provide remote code execution, it enables serious privilege or configuration escalation within the gateway.
Affected Systems
The flaw affects IBM DataPower Gateway products from version 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. All listed variants of the gateway are potentially impacted unless a patch has been applied.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. Because the EPSS score is not available, the exact likelihood of exploitation is uncertain, but the lack of a KEV listing suggests no confirmed exploits yet. Exploitation requires the attacker to have valid credentials for the gateway, after which the attacker can submit forged signed data. The impact is the potential to override security restrictions or inject configuration changes, which could compromise the confidentiality, integrity, and availability of the protected services.
OpenCVE Enrichment