Impact
IBM DataPower Gateway firmware versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6CD 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2 contain a buffer overflow that allows a remote attacker to execute arbitrary code. The vulnerability is caused by an out‑of‑bounds write in the gateway's request processing logic, which, if successfully exploited, would give an attacker full control over the device and compromise confidentiality, integrity, and availability of all services running on it. Based on the description, it is inferred that an attacker would trigger the write by sending specially crafted requests over the network to the gateway's management or data planes.
Affected Systems
Affected products include IBM DataPower Gateway releases 10.5, 10.6, 10.6CD and 11.0. The implicated versions are 10.5.0.0‑10.5.0.22, 10.6.0.0‑10.6.0.10, 10.6CD 10.6.1‑10.6.6, and 11.0.0.0‑11.0.0.2. All other versions are considered safe.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score is not listed, meaning the general likelihood of exploitation is unknown. The vulnerability is not included in CISA's KEV catalog. Given the remote nature of the attack vector and the potential for full code execution, the risk is elevated. The flaw originates from a classic out‑of‑bounds write (CWE‑787). No specific defensive measures are available beyond the vendor outage; therefore, the vendor's recommendation to upgrade is essential.
OpenCVE Enrichment