Impact
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross‑site scripting. An unauthenticated user can inject arbitrary JavaScript into the Web UI, which may alter intended behavior and potentially lead to disclosure of credentials within a trusted session. The flaw is a classic reflected or stored XSS, identified as CWE‑79.
Affected Systems
Affected versions are IBM DataPower Gateway 10.6.0.0 to 10.6.0.10, with the fix available in releases that include version 10.6.0.1010.6.0.11 and later. The vendor, IBM, recommends upgrading as soon as possible.
Risk and Exploitability
The CVSS score is 9.3, indicating high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered without authentication via the Web UI, the attack vector is likely remote, accessed over the network by any client. The lack of an available exploit probability metric makes assessment difficult, but the strong CVSS rating and ability to run arbitrary code in a user session imply a high risk if left unpatched.
OpenCVE Enrichment