Impact
IBM DataPower Gateway versions 10.5.0.0–10.5.0.22, 10.6.1–10.6.6, 10.6.0.0–10.6.0.10, and 11.0.0.0–11.0.0.2 contain a heap‑based buffer overflow that a remote attacker can exploit to execute arbitrary code. The flaw is identified as CWE‑122 and the CVSS score is 8.1, indicating high severity.
Affected Systems
Affected products are IBM DataPower Gateway 10.5.0, 10.6.0, 10.6CD, and 11.0.0. The versions listed above are vulnerable. Fixed releases include 10.5.0.23 or later, 10.6.0.11 or later, 10.6CD 10.6.1.0.0.3 or later, and 11.0.0.21 or later.
Risk and Exploitability
The CVSS score of 8.1 denotes a high‑impact attack that can compromise confidentiality, integrity, and availability. EPSS is not available, so the current public exploit probability is unclear; however, remote code execution is a high‑risk outcome. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation in the wild. To exploit, an attacker only needs network access to the gateway and can send crafted input that triggers the overflow, gaining arbitrary code execution.
OpenCVE Enrichment