CVE-2026-14888
- EPSS 0.37%
- Veröffentlicht 08.10.2026 14:02:38
- Zuletzt bearbeitet 09.10.2026 04:18:06
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
CVE-2026-14905
- EPSS 0.34%
- Veröffentlicht 08.10.2026 14:02:02
- Zuletzt bearbeitet 10.10.2026 04:18:11
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploi...
CVE-2026-14988
- EPSS 0.22%
- Veröffentlicht 08.10.2026 14:01:07
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to buffer overflow.
CVE-2026-14999
- EPSS 0.2%
- Veröffentlicht 08.10.2026 13:59:52
- Zuletzt bearbeitet 09.10.2026 04:18:07
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to bypass authentication by forging valid JSON Web Signatures due to improper verificatio...
CVE-2026-14992
- EPSS 0.31%
- Veröffentlicht 08.10.2026 13:58:48
- Zuletzt bearbeitet 09.10.2026 04:18:07
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
CVE-2026-14990
- EPSS 0.31%
- Veröffentlicht 08.10.2026 13:53:50
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...
CVE-2026-14991
- EPSS 0.41%
- Veröffentlicht 08.10.2026 13:50:49
- Zuletzt bearbeitet 10.10.2026 13:17:31
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and exec...
- EPSS 0.38%
- Veröffentlicht 08.10.2026 13:49:34
- Zuletzt bearbeitet 09.10.2026 04:18:10
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
CVE-2026-15784
- EPSS 0.39%
- Veröffentlicht 08.10.2026 13:32:55
- Zuletzt bearbeitet 09.10.2026 04:18:10
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
CVE-2026-15762
- EPSS 0.52%
- Veröffentlicht 08.10.2026 13:32:17
- Zuletzt bearbeitet 09.10.2026 04:18:09
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.