Heap-Based Buffer Overflow in IBM DataPower Gateway
CVE-2026-15824

8.2HIGH

What is CVE-2026-15824?

The vulnerability in IBM DataPower Gateway arises from a heap-based buffer overflow that can be exploited by remote attackers. This security flaw allows attackers to manipulate the application's memory, potentially leading to a denial of service condition. Users of the affected versions are advised to implement patches and workarounds provided in the IBM vendor advisory to mitigate risks associated with this vulnerability.

Affected Version(s)

DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22

DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10

DataPower Gateway 10.6CD 10.6.1 <= 10.6.6

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.