Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write in the RFC2047 encoded‑word parser allows a remote attacker to execute arbitrary code on IBM DataPower Gateway devices. The vulnerability is caused by improper bounds checking of RFC2047 input, which can corrupt memory and lead to full system compromise. Once exploited, the attacker can gain complete control over the gateway, read and modify configuration, inject malicious traffic, and potentially pivot to other assets on the network.

Affected Systems

The defect affects IBM DataPower Gateway releases 10.5.0.0 to 10.5.0.22, 10.6.1 to 10.6.6, 10.6.0.0 to 10.6.0.10, and 11.0.0.0 to 11.0.0.2. Supported vendors include IBM, with the fixed versions being 10.6CD 10.6.1 or later, 10.6.0 10.6.0.11 or later, 11.0.0 11.0.0.3 or later, and 10.5.0 10.5.0.23 or later. These firmware upgrades incorporate the patch that eliminates the out‑of‑bounds write.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity with a high likelihood of exploitation in a real‑world attack. The EPSS score is not available, but the lack of a known CISA KEV listing does not reduce its seriousness; the vulnerability is actively exploitable by sending crafted RFC2047 messages. Remote attackers can trigger the flaw by targeting the gateway with an encoded‑word payload; no local authentication or privilege escalation is required, making the attack vector likely to be over the network. Organizations should treat this as a high‑risk condition that demands immediate action.

Generated by OpenCVE AI on October 8, 2026 at 17:00 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. Known Issue: DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 Affected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23


OpenCVE Recommended Actions

  • Upgrade the DataPower Gateway firmware to the latest fixed version for your product line (10.6CD 10.6.1+ or newer, 10.6.0 10.6.0.11+ or newer, 11.0.0 11.0.0.3+ or newer, or 10.5.0 10.5.0.23+ or newer).
  • Restart the gateway after the firmware update and verify that the RFC2047 parser no longer accepts unsigned input from external sources.
  • If an upgrade cannot be performed immediately, isolate the gateway from untrusted networks and restrict inbound RFC2047 traffic until the patch is applied.

Generated by OpenCVE AI on October 8, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.
Title IBM DataPower Gateway Out-of-bounds Write
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T17:53:40.169Z

Reserved: 2026-07-20T19:40:57.359Z

Link: CVE-2026-16340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:16.610

Modified: 2026-10-08T14:16:54.593

Link: CVE-2026-16340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:15:05Z

Weaknesses