Impact
IBM DataPower Gateway software releases 10.5.0, 10.6.0, 10.6CD and 11.0.0 contain a buffer overflow that results from improper bounds checking. The flaw allows a local user to supply input that overflows a buffer, corrupts memory and ultimately executes arbitrary code on the host system.
Affected Systems
Affected vendors and products include IBM: DataPower Gateway 10.5.0, IBM: DataPower Gateway 10.6.0, IBM: DataPower Gateway 10.6CD, and IBM: DataPower Gateway 11.0.0. Vulnerable releases span 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. Fixed releases start with 10.5.0.23, 10.6.0.1010, 10.6.1, and 11.0.0.211 respectively.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. EPSS data is not available, so the exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker must have local access to the device and sufficient privileges to supply the malicious input that triggers the overflow. Successful exploitation results in arbitrary code execution on the underlying system.
OpenCVE Enrichment