Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
Published: 2026-10-08
Score: 8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 contain a stack‑based buffer overflow that enables a remote authenticated attacker to execute arbitrary code on the device. The flaw arises from insufficient bounds checking of input data processed by the gateway, allowing an attacker to overflow a buffer and gain code execution.

Affected Systems

IBM DataPower Gateway is the affected product. Vulnerable releases include the 10.5.0 family (up to patch 22), the 10.6.0 series (up to patch 10), the 10.6CD editions (10.6.1 through 10.6.6), and the 11.0.0 series (up to patch 2). All affected machines run versions that expose the gateway components handling external network traffic.

Risk and Exploitability

The CVSS score of 8 classifies the vulnerability as high severity. EPSS data is unavailable, and the flaw is not listed in the CISA KEV catalog. Because the exploitation requires authenticated access, the attacker must first compromise administrator credentials or obtain privileged login to the gateway. Once authenticated, the buffer overflow can be triggered via normal gateway operations, resulting in full system compromise. The attack vector is inferred to be remote network access to the gateway’s processing interfaces.

Generated by OpenCVE AI on October 8, 2026 at 16:25 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade IBM DataPower Gateway to a patched release beyond the affected versions: 10.5.0.23 or later, 10.6.0.11 or later, 10.6CD 10.6.1.0 or later, or 11.0.0.3 or later.
  • Restrict remote management of the gateway to trusted administrators and enforce strong authentication and least‑privilege controls.
  • Disable any unnecessary services or modules that accept external traffic on the gateway to reduce the attack surface while patching.

Generated by OpenCVE AI on October 8, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
Title IBM DataPower Gateway Buffer Overflow
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-121
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T17:53:13.150Z

Reserved: 2026-07-14T18:54:49.891Z

Link: CVE-2026-15781

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:52.037

Modified: 2026-10-08T14:16:52.037

Link: CVE-2026-15781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow