Sceawere
Vulnerability Detail
CVE-2026-16170UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM DataPower Heap Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 4h ago
- Vendor
- IBM
- Product
- DataPower Gateway 10.6CD
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to a heap buffer overflow.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-08T13:17:15.660Z",
"pubdate": "2026-10-08T13:17:15.660Z",
"executiveSummary": "A critical security vulnerability identified as a heap buffer overflow exists within IBM DataPower Gateway. This flaw permits a remote, unauthenticated attacker to induce a denial-of-service (DoS) condition on affected systems.\nThe vulnerability affects multiple firmware versions across the 10.5, 10.6, and 11.0 release lines. The heap-based memory corruption arises during the processing of specifically crafted inputs, leading to service instability or application crashes.\nThe risk is categorized as high due to the potential for service disruption, which impacts business continuity for organizations relying on DataPower for API management and security. There are no requirements for valid user credentials or elevated privileges to initiate the exploitation, as the vulnerability is reachable over the network. Organizations must evaluate their current firmware deployments against the affected version list to determine exposure levels.",
"technicalDetails": "The vulnerability resides in the memory management subsystem of IBM DataPower Gateway. Specifically, it manifests as a heap buffer overflow, a condition occurring when an application writes data exceeding the allocated boundaries of a buffer on the heap memory segment. By providing a maliciously crafted request that triggers improper bounds checking within the gateway's processing logic, an attacker can overwrite adjacent heap memory regions.\nThe exploitation flow initiates when the attacker sends a specially formatted network request to the affected DataPower Gateway instance. The gateway, while attempting to parse or process this input, fails to enforce strict length validation on the incoming data buffer. As the gateway copies the oversized input into a fixed-size heap allocation, the data overflows the buffer's intended boundary. This corruption typically disrupts critical pointers or heap metadata, causing the process to enter an inconsistent state or execute invalid instructions, ultimately resulting in an unrecoverable process crash.\nAffected software versions include IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2. The vulnerability is network-accessible, meaning that any attacker with IP connectivity to the gateway's listener interface can potentially trigger the overflow. Authentication is not required, as the flaw resides in the protocol handling or pre-authentication input processing layers of the appliance.\nPost-exploitation, the primary impact is a denial-of-service condition, rendering the gateway incapable of processing legitimate traffic. This interruption can have severe consequences in enterprise environments where DataPower serves as a primary gateway for secure API traffic. While the primary documented symptom is a denial-of-service, heap overflows of this nature are theoretically capable of allowing arbitrary code execution if an attacker can precisely control the heap layout and the data written; however, in this context, the primary risk remains the loss of service availability."
}