Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Local Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM DataPower Gateway software releases 10.5.0, 10.6.0, 10.6CD and 11.0.0 contain a buffer overflow that results from improper bounds checking. The flaw allows a local user to supply input that overflows a buffer, corrupts memory and ultimately executes arbitrary code on the host system.

Affected Systems

Affected vendors and products include IBM: DataPower Gateway 10.5.0, IBM: DataPower Gateway 10.6.0, IBM: DataPower Gateway 10.6CD, and IBM: DataPower Gateway 11.0.0. Vulnerable releases span 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2. Fixed releases start with 10.5.0.23, 10.6.0.1010, 10.6.1, and 11.0.0.211 respectively.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. EPSS data is not available, so the exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker must have local access to the device and sufficient privileges to supply the malicious input that triggers the overflow. Successful exploitation results in arbitrary code execution on the underlying system.

Generated by OpenCVE AI on October 8, 2026 at 16:47 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade the DataPower Gateway firmware to a version that contains the fix (for example, 10.6.1 or later for the 10.6CD branch, 10.6.0.1010 or later for 10.6.0, 11.0.0.211 or later for 11.0.0, and 10.5.0.23 or later for 10.5.0).
  • Restrict local user accounts on the device to the minimum level of privileges required for day‑to‑day operations, removing any accounts with unnecessary administrative rights.
  • Avoid using configuration functions that trigger the vulnerable memory path until the firmware update is applied, and isolate the device from untrusted networks if an update cannot be performed immediately.

Generated by OpenCVE AI on October 8, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
Title IBM DataPower Gateway Out-of-bounds Write
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T15:59:00.028Z

Reserved: 2026-07-07T18:46:13.071Z

Link: CVE-2026-14991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:51.740

Modified: 2026-10-08T16:17:07.553

Link: CVE-2026-14991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:16Z

Weaknesses