Description
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting leading to credential disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross‑site scripting. An unauthenticated user can inject arbitrary JavaScript into the Web UI, which may alter intended behavior and potentially lead to disclosure of credentials within a trusted session. The flaw is a classic reflected or stored XSS, identified as CWE‑79.

Affected Systems

Affected versions are IBM DataPower Gateway 10.6.0.0 to 10.6.0.10, with the fix available in releases that include version 10.6.0.1010.6.0.11 and later. The vendor, IBM, recommends upgrading as soon as possible.

Risk and Exploitability

The CVSS score is 9.3, indicating high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered without authentication via the Web UI, the attack vector is likely remote, accessed over the network by any client. The lack of an available exploit probability metric makes assessment difficult, but the strong CVSS rating and ability to run arbitrary code in a user session imply a high risk if left unpatched.

Generated by OpenCVE AI on October 8, 2026 at 16:23 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT501991 https://www.ibm.com/mysupport/s/defect/aCIgJ000000Jra5/dt501991 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11


OpenCVE Recommended Actions

  • Upgrade IBM DataPower Gateway to version 10.6.0.1010.6.0.11 or later.
  • If an immediate upgrade is not possible, restrict access to the Web UI with network segmentation or firewall rules to limit unauthenticated users.
  • If the Web UI must remain accessible, implement a strict Content Security Policy or ensure proper input sanitization to mitigate XSS.

Generated by OpenCVE AI on October 8, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM DataPower Gateway affected by cross-site scripting
First Time appeared Ibm
Ibm datapower Gateway 1060
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1060
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Ibm Datapower Gateway 1060
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:34:38.465Z

Reserved: 2026-07-07T18:45:52.925Z

Link: CVE-2026-14990

cve-icon Vulnrichment

Updated: 2026-10-08T14:34:34.933Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:51.603

Modified: 2026-10-08T15:17:50.103

Link: CVE-2026-14990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')