Impact
The vulnerability is a classic out‑of‑bounds memory write that occurs while the gateway derives cryptographic keys. An attacker who can authenticate to the system can trigger the flaw, causing the system to crash or become unresponsive. The impact is limited to service interruption; there is no known path to data disclosure or code execution.
Affected Systems
IBM DataPower Gateway within the 11.0.0.0 through 11.0.0.2 release. The fixed release is available as 11.0.0.211.0.0.3.
Risk and Exploitability
The CVSS score of 7.7 classifies this as a high‑severity issue. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalogue. Attackers would need authenticated access to the gateway and they can exploit the bug remotely by sending a crafted request that triggers the improper memory allocation. Given the high severity and the vulnerability’s remote nature, organizations should prioritize remediation.
OpenCVE Enrichment