Impact
The vulnerability is a buffer overflow that can occur when the device processes certain inputs, allowing an attacker to read memory beyond array bounds or write arbitrary data. An attacker who succeeds could execute arbitrary code with the privileges of the DataPower service, potentially taking control of the device and compromising connected systems. The weakness corresponds to CWE-125 and can lead to confidentiality, integrity.
Affected Systems
Affected are IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. Upgrades are available for all these releases, including 10.6.1, 10.6.6, 11.0.0.2, and earlier point releases.
Risk and Exploitability
The CVSS score of 6.5 indicates substantial risk. Although the EPSS score is not provided, the lack of an EPSS value does not imply no threat; the vulnerability remains exploitable if an attacker can reach the device. IBM has not listed the issue in the CISA KEV catalog, but the out‑of‑bounds read is a classic remote exploitation vector that should be mitigated promptly. Until a patch is applied, the device is potentially vulnerable to remote code execution via network traffic.
OpenCVE Enrichment