Denial of Service Vulnerability in IBM DataPower Gateway
CVE-2026-16178

7.5HIGH

What is CVE-2026-16178?

A vulnerability in IBM DataPower Gateway allows a remote attacker to exploit improper input validation, potentially leading to a denial of service. The affected versions span multiple releases, including 10.5, 10.6, and 11.0, exposing systems to unexpected outages or disruptions. It is essential to review the available vendor advisory and implement necessary patches to safeguard against these risks.

Affected Version(s)

DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22

DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10

DataPower Gateway 10.6CD 10.6.1 <= 10.6.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.