CVE-2026-16182
- EPSS 0.27%
- Veröffentlicht 08.10.2026 13:17:16
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an attacker to cause a denial of service due to a NULL pointer dereference in GraphQL vari...
CVE-2026-16181
- EPSS 0.33%
- Veröffentlicht 08.10.2026 13:17:16
- Zuletzt bearbeitet 09.10.2026 04:18:10
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
CVE-2026-16179
- EPSS 0.32%
- Veröffentlicht 08.10.2026 13:17:16
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an attacker to cause a heap buffer underwrite and potentially crash the service.
CVE-2026-16178
- EPSS 0.39%
- Veröffentlicht 08.10.2026 13:17:16
- Zuletzt bearbeitet 10.10.2026 04:18:11
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper input validation.
CVE-2026-16177
- EPSS 0.31%
- Veröffentlicht 08.10.2026 13:17:15
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.
CVE-2026-16176
- EPSS 0.39%
- Veröffentlicht 08.10.2026 13:17:15
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper validation of the length field during memory...
CVE-2026-16170
- EPSS 0.39%
- Veröffentlicht 08.10.2026 13:17:15
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
CVE-2026-16169
- EPSS 0.39%
- Veröffentlicht 08.10.2026 13:17:15
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.
CVE-2026-14521
- EPSS 0.15%
- Veröffentlicht 08.10.2026 13:17:15
- Zuletzt bearbeitet 10.10.2026 04:18:11
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ...
CVE-2026-16167
- EPSS 0.33%
- Veröffentlicht 08.10.2026 13:14:13
- Zuletzt bearbeitet 08.10.2026 20:49:50
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper bounds checking.