Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to buffer overflow.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Upgrade Immediately
AI Analysis

Impact

The vulnerability is a buffer overflow that can occur when the device processes certain inputs, allowing an attacker to read memory beyond array bounds or write arbitrary data. An attacker who succeeds could execute arbitrary code with the privileges of the DataPower service, potentially taking control of the device and compromising connected systems. The weakness corresponds to CWE-125 and can lead to confidentiality, integrity.

Affected Systems

Affected are IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. Upgrades are available for all these releases, including 10.6.1, 10.6.6, 11.0.0.2, and earlier point releases.

Risk and Exploitability

The CVSS score of 6.5 indicates substantial risk. Although the EPSS score is not provided, the lack of an EPSS value does not imply no threat; the vulnerability remains exploitable if an attacker can reach the device. IBM has not listed the issue in the CISA KEV catalog, but the out‑of‑bounds read is a classic remote exploitation vector that should be mitigated promptly. Until a patch is applied, the device is potentially vulnerable to remote code execution via network traffic.

Generated by OpenCVE AI on October 8, 2026 at 16:20 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade IBM DataPower Gateway to 10.6.1, 10.6.6, or 11.0.0.2 or later, as applicable to your deployment.
  • Limit exposure of the DataPower Gateway by restricting inbound traffic to and access control lists.
  • Review and restrict configuration options that enable external management interfaces if they are not required for your environment.

Generated by OpenCVE AI on October 8, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to buffer overflow.
Title IBM DataPower Gateway Out-of-bounds Read
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:01:07.902Z

Reserved: 2026-07-07T18:42:10.372Z

Link: CVE-2026-14988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:49.973

Modified: 2026-10-08T15:17:49.973

Link: CVE-2026-14988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses