Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Published: 2026-10-08
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM DataPower Gateway firmware versions 10.5.0.0 through 10.5.0.22, 10.6.0.0 through 10.6.0.10, 10.6CD 10.6.1 through 10.6.6, and 11.0.0.0 through 11.0.0.2 contain a buffer overflow that allows a remote attacker to execute arbitrary code. The vulnerability is caused by an out‑of‑bounds write in the gateway's request processing logic, which, if successfully exploited, would give an attacker full control over the device and compromise confidentiality, integrity, and availability of all services running on it. Based on the description, it is inferred that an attacker would trigger the write by sending specially crafted requests over the network to the gateway's management or data planes.

Affected Systems

Affected products include IBM DataPower Gateway releases 10.5, 10.6, 10.6CD and 11.0. The implicated versions are 10.5.0.0‑10.5.0.22, 10.6.0.0‑10.6.0.10, 10.6CD 10.6.1‑10.6.6, and 11.0.0.0‑11.0.0.2. All other versions are considered safe.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score is not listed, meaning the general likelihood of exploitation is unknown. The vulnerability is not included in CISA's KEV catalog. Given the remote nature of the attack vector and the potential for full code execution, the risk is elevated. The flaw originates from a classic out‑of‑bounds write (CWE‑787). No specific defensive measures are available beyond the vendor outage; therefore, the vendor's recommendation to upgrade is essential.

Generated by OpenCVE AI on October 8, 2026 at 16:28 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade the DataPower Gateway firmware to a version that includes the fix (for example, 10.6.0.11, 10.6CD 10.6.1, or 11.0.0.211 or later).
  • Until the upgrade can be performed, restrict external network traffic to the gateway or place the device in a trusted zone to limit exposure.
  • Apply network segmentation or firewall rules that allow only trusted management IPs to reach the gateway's administrative interfaces, reducing the attack surface.

Generated by OpenCVE AI on October 8, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Title IBM DataPower Gateway Out-of-bounds Write
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T14:03:26.223Z

Reserved: 2026-07-14T19:07:35.806Z

Link: CVE-2026-15784

cve-icon Vulnrichment

Updated: 2026-10-08T14:03:22.240Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:16:52.220

Modified: 2026-10-08T15:17:50.740

Link: CVE-2026-15784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses