Description
IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to cause a denial of service due to improper memory allocation during key derivation.
Published: 2026-10-08
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a classic out‑of‑bounds memory write that occurs while the gateway derives cryptographic keys. An attacker who can authenticate to the system can trigger the flaw, causing the system to crash or become unresponsive. The impact is limited to service interruption; there is no known path to data disclosure or code execution.

Affected Systems

IBM DataPower Gateway within the 11.0.0.0 through 11.0.0.2 release. The fixed release is available as 11.0.0.211.0.0.3.

Risk and Exploitability

The CVSS score of 7.7 classifies this as a high‑severity issue. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need authenticated access to the gateway and they can exploit the bug remotely by sending a crafted request that triggers the improper memory allocation. Given the high severity and the vulnerability’s remote nature, organizations should prioritize remediation.

Generated by OpenCVE AI on October 8, 2026 at 16:17 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT501893 https://www.ibm.com/mysupport/s/defect/aCIgJ000000Joyo/dt501893 Affected VersionsFixed in ReleaseIBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3


OpenCVE Recommended Actions

  • Upgrade the DataPower Gateway to the fixed release 11.0.0.211.0.0.3 as soon as possible.
  • Implement strict input validation on all incoming requests to ensure that length parameters are checked before memory allocation, following best practices for preventing buffer overflows.
  • When an upgrade is not immediately feasible, restrict remote authenticated access to the gateway and monitor for sign‑off events such as repeated authentication failures or abnormal memory allocation errors.

Generated by OpenCVE AI on October 8, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to cause a denial of service due to improper memory allocation during key derivation.
Title IBM DataPower Gateway Out-of-bounds Write
First Time appeared Ibm
Ibm datapower Gateway 1100
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Ibm Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:04:30.900Z

Reserved: 2026-07-02T18:36:38.976Z

Link: CVE-2026-14507

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:49.283

Modified: 2026-10-08T15:17:49.283

Link: CVE-2026-14507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses