Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote administrative access through authentication bypass
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is caused by a failure to reject empty passwords during LDAP authentication on IBM DataPower Gateway devices. An attacker who can reach the LDAP authentication endpoint can supply an empty password and gain administrative access without legitimate credentials. The resulting privileges allow full control over the gateway, compromising confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑287, Authentication Bypass via Password Manipulation.

Affected Systems

The affected products are IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. The vulnerability has been fixed in the following releases: IBM DataPower Gateway 10.6CD 10.6.1, 10.6.6; IBM DataPower Gateway 10.6.0 10.6.0.10; IBM DataPower Gateway 11.0.0 11.0.0.2; and IBM DataPower Gateway 10.5.0 10.5.0.22.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, so the exact current exploitation probability is unknown, but the lack of a practical mitigation and the high score suggest a high likelihood of exploitation in the field. The vulnerability is not listed in the CISA KEV catalog, which may be due to its recent discovery. The likely attack vector is remote authentication over the network, requiring that the attacker can interact with the LDAP service configured on the gateway.

Generated by OpenCVE AI on October 8, 2026 at 16:06 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade the IBM DataPower Gateway to at least the fixed releases: 10.6CD 10.6.1 or later, 10.6.0 10.6.0.10 or later, 11.0.0 11.0.0.2 or later, and 10.5.0 10.5.0.22 or later.
  • Verify that LDAP authentication is configured to disallow empty passwords by checking the authentication policy after the upgrade.
  • If LDAP authentication is not required for management, disable it or restrict the gateway’s management interface to trusted networks and enforce least‑privilege access controls.

Generated by OpenCVE AI on October 8, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.
Title IBM DataPower Gateway Improper Authentication
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:05:27.678Z

Reserved: 2026-07-02T18:06:31.223Z

Link: CVE-2026-14502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:49.150

Modified: 2026-10-08T15:17:49.150

Link: CVE-2026-14502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses