Impact
A race condition in IBM DataPower Gateway's XML‑Firewall handling of the X‑Client‑IP header allows request state contamination across concurrent requests. An attacker can exploit this to masquerade as another client and learn the IP addresses of other users. The weakness is a race condition (CWE‑362) that compromises confidentiality and integrity of network information.
Affected Systems
IBM DataPower Gateway versions 10.5.0 through 10.5.0.21, 10.6.0 through 10.6.0.9, and 11.0.0 through 11.0.0.1 are affected. These versions correspond to Software Releases 10.5.0.0‑10.5.0.211, 10.6.0.0‑10.6.0.910, and 11.0.0.0‑11.0.0.111.0.0.2.
Risk and Exploitability
The CVSS score of 4.2 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting limited current exploitation. The attack vector likely involves sending crafted HTTP requests with the X‑Client‑IP header to a vulnerable XML‑Firewall service, and the race condition requires concurrent requests to succeed.
OpenCVE Enrichment