CVE-2026-14269: fallo crítico en IBM DataPower Gateway 10.5.0
IBM DataPower Gateway Buffer Overflow
Publicada el
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.8
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
IBM · DataPower Gateway 10.5.0IBM · DataPower Gateway 10.6.0IBM · DataPower Gateway 10.6CDIBM · DataPower Gateway 11.0.0CVEs relacionadas — IBM DataPower Gateway 10.5.0
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-12733HIGHIBM DataPower Gateway affected by denial of serviceEPSS 0.5%CVE-2025-36374MEDIUMIBM DataPower Gateway affected by XML external entity injectionEPSS 0.4%CVE-2025-36373MEDIUMIncorrect administrative access control in IBM DataPower GatewayEPSS 0.3%CVE-2025-36375MEDIUMIBM DataPower Gateway vulnerable to CSRFEPSS 0.2%CVE-2026-7366MEDIUMIBM DataPower Gateway affected by HTTP request header leakage in XML-FirewallEPSS 0.2%CVE-2026-13257MEDIUMIBM DataPower Gateway Insufficient Verification of Data AuthenticityEPSS —