Impact
A buffer overflow in IBM DataPower Gateway allows an out‑of‑bounds write that can lead to arbitrary code execution or denial of service. The flaw is categorized as CWE‑787 and can be triggered when a gateway process handles malformed input.
Affected Systems
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1.0 through 10.6.6.0, and 11.0.0.0 through 11.0.0.2 are affected. The vulnerability has been fixed in revisions beginning with IBM DataPower Gateway 10.6CD 10.6.1, 10.6.6.1, 11.0.0.21, 10.5.0.23, and 10.6.0.101.
Risk and Exploitability
The CVSS score of 9.8 marks this a critical risk, and the EPSS score is currently unavailable, indicating limited data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog, but the severity and lack of mitigation could still lead to successful exploits. Likely attack vectors involve remote ingestion of crafted traffic to the gateway’s management or data interfaces, enabling an attacker to trigger the overflow and gain arbitrary code execution.
OpenCVE Enrichment