Out-of-Bounds Read Vulnerability in IBM DataPower Gateway
CVE-2026-16177
5.3MEDIUM
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-16177?
IBM DataPower Gateway versions 10.5.0.0 to 10.5.0.22, 10.6.1 to 10.6.6, 10.6.0.0 to 10.6.0.10, and 11.0.0.0 to 11.0.0.2 are susceptible to an out-of-bounds read vulnerability. Exploitation of this flaw allows remote authenticated attackers to access sensitive information, potentially compromising confidentiality. Administrators are advised to review the vendor advisory and apply the necessary patches to mitigate risks.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6