Remote Denial of Service Risk in IBM DataPower Gateway
CVE-2026-16167

7.5HIGH

What is CVE-2026-16167?

The vulnerability in IBM DataPower Gateway allows remote attackers to exploit improper bounds checking, potentially leading to a denial of service. Affected versions include those ranging from 10.5.0.0 to 11.0.0.2, making it crucial for users to apply the latest patches. Visit IBM's advisory for more details to secure your infrastructure.

Affected Version(s)

DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22

DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10

DataPower Gateway 10.6CD 10.6.1 <= 10.6.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.