CVE-2026-14269
- EPSS 0.48%
- Veröffentlicht 08.10.2026 14:30:01
- Zuletzt bearbeitet 09.10.2026 04:18:05
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker c...
CVE-2026-13257
- EPSS 0.13%
- Veröffentlicht 08.10.2026 14:08:40
- Zuletzt bearbeitet 10.10.2026 04:18:10
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.
CVE-2026-13258
- EPSS 0.16%
- Veröffentlicht 08.10.2026 14:08:07
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript co...
CVE-2026-14273
- EPSS 0.09%
- Veröffentlicht 08.10.2026 14:07:38
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a local attacker to obtain sensitive information due to improper authorization.
CVE-2026-14496
- EPSS 0.3%
- Veröffentlicht 08.10.2026 14:06:54
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
CVE-2026-14497
- EPSS 0.59%
- Veröffentlicht 08.10.2026 14:06:18
- Zuletzt bearbeitet 09.10.2026 04:18:05
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptograph...
CVE-2026-14502
- EPSS 0.39%
- Veröffentlicht 08.10.2026 14:05:27
- Zuletzt bearbeitet 09.10.2026 18:17:07
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP auth...
CVE-2026-14507
- EPSS 0.28%
- Veröffentlicht 08.10.2026 14:04:30
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to cause a denial of service due to improper memory allocation during key derivation.
CVE-2026-14508
- EPSS 0.24%
- Veröffentlicht 08.10.2026 14:03:49
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service and obtain sensitive information due to a use-after-free.
CVE-2026-14509
- EPSS 0.27%
- Veröffentlicht 08.10.2026 14:03:02
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to algorithmic complexity in linked-list traversal.