Impact
This vulnerability is caused by a failure to reject empty passwords during LDAP authentication on IBM DataPower Gateway devices. An attacker who can reach the LDAP authentication endpoint can supply an empty password and gain administrative access without legitimate credentials. The resulting privileges allow full control over the gateway, compromising confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑287, Authentication Bypass via Password Manipulation.
Affected Systems
The affected products are IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. The vulnerability has been fixed in the following releases: IBM DataPower Gateway 10.6CD 10.6.1, 10.6.6; IBM DataPower Gateway 10.6.0 10.6.0.10; IBM DataPower Gateway 11.0.0 11.0.0.2; and IBM DataPower Gateway 10.5.0 10.5.0.22.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, so the exact current exploitation probability is unknown, but the lack of a practical mitigation and the high score suggest a high likelihood of exploitation in the field. The vulnerability is not listed in the CISA KEV catalog, which may be due to its recent discovery. The likely attack vector is remote authentication over the network, requiring that the attacker can interact with the LDAP service configured on the gateway.
OpenCVE Enrichment