Cross-Site Scripting Vulnerability in IBM DataPower Gateway
CVE-2026-14990
9.3CRITICAL
What is CVE-2026-14990?
IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 are susceptible to a cross-site scripting vulnerability. This flaw allows an unauthenticated attacker to inject arbitrary JavaScript code into the Web UI, potentially compromising the integrity of a user's session and leading to unauthorized access to sensitive credentials. Immediate action is recommended to mitigate risks associated with this vulnerability.
Affected Version(s)
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10