Impact
IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 contain a stack‑based buffer overflow that enables a remote authenticated attacker to execute arbitrary code on the device. The flaw arises from insufficient bounds checking of input data processed by the gateway, allowing an attacker to overflow a buffer and gain code execution.
Affected Systems
IBM DataPower Gateway is the affected product. Vulnerable releases include the 10.5.0 family (up to patch 22), the 10.6.0 series (up to patch 10), the 10.6CD editions (10.6.1 through 10.6.6), and the 11.0.0 series (up to patch 2). All affected machines run versions that expose the gateway components handling external network traffic.
Risk and Exploitability
The CVSS score of 8 classifies the vulnerability as high severity. EPSS data is unavailable, and the flaw is not listed in the CISA KEV catalog. Because the exploitation requires authenticated access, the attacker must first compromise administrator credentials or obtain privileged login to the gateway. Once authenticated, the buffer overflow can be triggered via normal gateway operations, resulting in full system compromise. The attack vector is inferred to be remote network access to the gateway’s processing interfaces.
OpenCVE Enrichment