9.8
CVE-2026-16340
- EPSS 0.49%
- Veröffentlicht 08.10.2026 13:17:16
- Zuletzt bearbeitet 09.10.2026 04:18:10
- Erkennungen
IBM DataPower Gateway Out-of-bounds Write
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
DataPower Gateway 10.6CD
Version <=
10.6.6
Version
10.6.1
Status
affected
HerstellerIBM
≫
Produkt
DataPower Gateway 10.6.0
Version <=
10.6.0.10
Version
10.6.0.0
Status
affected
HerstellerIBM
≫
Produkt
DataPower Gateway 11.0.0
Version <=
11.0.0.2
Version
11.0.0.0
Status
affected
HerstellerIBM
≫
Produkt
DataPower Gateway 10.5.0
Version <=
10.5.0.22
Version
10.5.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.402 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.ibm.com/support/pages/node/7289775