Impact
The flaw is an out‑of‑bounds write that permits a remote attacker to execute arbitrary code on IBM DataPower Gateway appliances. Classified as CWE‑787, the vulnerability allows the attacker to corrupt control data, potentially leading to full compromise of the device. The impact includes loss of confidentiality, integrity, and availability for the affected system and any downstream services.
Affected Systems
IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2 are affected. The vulnerability is fixed in subsequent releases: 10.5.0.23, 10.6.0.11, 10.6CD 10.6.6.1, and 11.0.0.3.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. EPSS is not available and the vulnerability is not listed in CISA KEV, implying no widespread exploitation yet. However, the flaw can be triggered remotely without authentication from any system that can reach the gateway, giving an attacker remote code execution privileges over the appliance.
OpenCVE Enrichment