Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is an out‑of‑bounds write that permits a remote attacker to execute arbitrary code on IBM DataPower Gateway appliances. Classified as CWE‑787, the vulnerability allows the attacker to corrupt control data, potentially leading to full compromise of the device. The impact includes loss of confidentiality, integrity, and availability for the affected system and any downstream services.

Affected Systems

IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2 are affected. The vulnerability is fixed in subsequent releases: 10.5.0.23, 10.6.0.11, 10.6CD 10.6.6.1, and 11.0.0.3.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. EPSS is not available and the vulnerability is not listed in CISA KEV, implying no widespread exploitation yet. However, the flaw can be triggered remotely without authentication from any system that can reach the gateway, giving an attacker remote code execution privileges over the appliance.

Generated by OpenCVE AI on October 8, 2026 at 16:49 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade to the fixed release for your DataPower Gateway version; for example, install 10.5.0.23, 10.6.0.11, 10.6CD 10.6.6.1, or 11.0.0.3 as appropriate.
  • While the upgrade is pending, restrict external access to the gateway by allowing only trusted management IPs or by placing the device behind a firewall that permits only known, secure traffic.
  • Enable comprehensive logging of inbound traffic to the gateway and review logs for anomalous patterns that could indicate buffer‑overrun attempts.

Generated by OpenCVE AI on October 8, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Title IBM DataPower Gateway Out-of-bounds Write
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T17:32:57.238Z

Reserved: 2026-07-14T18:24:12.650Z

Link: CVE-2026-15762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:51.880

Modified: 2026-10-08T14:16:51.880

Link: CVE-2026-15762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:16Z

Weaknesses