4.2
CVE-2026-7366
- EPSS 0.16%
- Veröffentlicht 12.08.2026 21:19:41
- Zuletzt bearbeitet 04.10.2026 18:16:34
- Erkennungen
IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing, X‑Client‑IP values may be contaminated across requests, enabling IP spoofing and disclosure of other clients’ IP addresses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Datapower Gateway Version >= 10.5.0.0 < 10.5.0.22
Ibm ≫ Datapower Gateway Version >= 10.6.0.0 < 10.6.0.10
Ibm ≫ Datapower Gateway Version >= 11.0.0.0 < 11.0.0.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 4.2 | 1.6 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://www.ibm.com/support/pages/node/7282770