Description
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
Published: 2026-08-12
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in IBM DataPower Gateway's XML‑Firewall handling of the X‑Client‑IP header allows request state contamination across concurrent requests. An attacker can exploit this to masquerade as another client and learn the IP addresses of other users. The weakness is a race condition (CWE‑362) that compromises confidentiality and integrity of network information.

Affected Systems

IBM DataPower Gateway versions 10.5.0 through 10.5.0.21, 10.6.0 through 10.6.0.9, and 11.0.0 through 11.0.0.1 are affected. These versions correspond to Software Releases 10.5.0.0‑10.5.0.211, 10.6.0.0‑10.6.0.910, and 11.0.0.0‑11.0.0.111.0.0.2.

Risk and Exploitability

The CVSS score of 4.2 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting limited current exploitation. The attack vector likely involves sending crafted HTTP requests with the X‑Client‑IP header to a vulnerable XML‑Firewall service, and the race condition requires concurrent requests to succeed.

Generated by OpenCVE AI on August 13, 2026 at 02:11 UTC.

Remediation

Vendor Solution

IBM strongly advises upgrading as soon as possible. APAR: DT469107 Affected VersionsFixed in ReleaseIBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.111.0.0.2IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2110.5.0.22IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.910.6.0.10


Vendor Workaround

Disable persistent connections to an XML Firewall service or don't set the X-Client-IP header on the client request.


OpenCVE Recommended Actions

  • Upgrade to a patched IBM DataPower Gateway release (11.0.0.111.0.0.2 or later, 10.6.0.910 or later, or 10.5.0.211 or later).
  • Disable persistent connections to the XML‑Firewall service or ensure that the X‑Client‑IP header is not set on client requests as a temporary workaround.
  • If the system must use persistent connections, monitor traffic for unexpected X‑Client‑IP values and enforce strict validation to prevent header contamination.

Generated by OpenCVE AI on August 13, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm datapower Gateway
CPEs cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
Vendors & Products Ibm datapower Gateway

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
Title IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 1100
Weaknesses CWE-362
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 1100
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Datapower Gateway Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 1100
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T13:05:37.050Z

Reserved: 2026-04-28T20:55:47.917Z

Link: CVE-2026-7366

cve-icon Vulnrichment

Updated: 2026-08-13T13:05:00.564Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T22:17:17.780

Modified: 2026-08-17T18:20:21.940

Link: CVE-2026-7366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:15:02Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')