9.8
CVE-2026-14992
- EPSS 0.31%
- Veröffentlicht 08.10.2026 13:58:48
- Zuletzt bearbeitet 09.10.2026 04:18:07
- Erkennungen
IBM DataPower Gateway Out-of-bounds Write
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
DataPower Gateway 10.6CD
Version <=
10.6.6
Version
10.6.1
Status
affected
HerstellerIBM
≫
Produkt
DataPower Gateway 10.6.0
Version <=
10.6.0.10
Version
10.6.0.0
Status
affected
HerstellerIBM
≫
Produkt
DataPower Gateway 11.0.0
Version <=
11.0.0.2
Version
11.0.0.0
Status
affected
HerstellerIBM
≫
Produkt
DataPower Gateway 10.5.0
Version <=
10.5.0.22
Version
10.5.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.221 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.ibm.com/support/pages/node/7289775