Known vulnerabilities in IBM DataPower Gateway

Software CPE: cpe:2.3:a:ibm_corporation:ibm_datapower_gateway:*:*:*:*:*:*:*:*
Total vulnerabilities: 430
Public exploits: 19
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM DataPower Gateway IBM DataPower Gateway is affected by 430 known vulnerabilities: 1 critical, 23 high, 88 medium, 318 low Critical High Medium Low

Vulnerabilities (430)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU127592 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42264
CWE-1321 Medium
No
No
10.5.0.22, 10.6.0.10, 11.0.0.2 24.04.2026 SB20260424168
SB2026061999
SB20260619101
and 10 more
#VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-29063
CWE-1321 Medium
No
No
10.6.0.9, 11.0.0.0 02.04.2026 SB2026040246
SB2026040612
SB2026040627
and 35 more
#VU123159 - Incorrect Calculation of Buffer Size
CVE-2026-1188
CWE-131 High
No
No
10.5.0.21, 10.6.0.9, 11.0.0.0 24.02.2026 SB2026022412
SB2026022413
SB2026022531
and 46 more
#VU122150 - Uncaught Exception
CVE-2026-25128
CWE-248 Medium
Available
No
10.5.0.21, 10.6.0.9, 11.0.0.0 30.01.2026 SB2026013034
SB2026030312
SB2026030633
and 7 more
#VU122085 - NULL Pointer Dereference
CVE-2026-22795
CWE-476 Medium
No
No
10.5.0.21, 10.6.0.9, 11.0.0.0 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 48 more
#VU121928 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-13465
CWE-1321 Medium
No
No
10.5.0.21, 10.6.0.9, 11.0.0.0 22.01.2026 SB2026012209
SB2026012701
SB2026012744
and 69 more
#VU121727 - Improper input validation
CVE-2026-21945
CWE-20 Medium
No
No
10.5.0.21, 10.6.0.9, 11.0.0.0 20.01.2026 SB20260120152
SB20260120153
SB20260120154
and 96 more
#VU121729 - Improper input validation
CVE-2026-21933
CWE-20 Medium
No
No
10.5.0.21, 10.6.0.9, 11.0.0.0 20.01.2026 SB20260120152
SB20260120153
SB20260120154
and 90 more
#VU121159 - Resource exhaustion
CVE-2025-15284
CWE-400 Medium
No
No
10.5.0.21, 10.6.0.9, 11.0.0.0 12.01.2026 SB2026011229
SB2026011326
SB2026011926
and 38 more
#VU120834 - Integer overflow
CVE-2022-50865
CWE-190 Low
No
No
10.5.0.21, 10.6.0.9 30.12.2025 SB20251230279
SB2026020210
SB2026020211
and 13 more
#VU118753 - Resource exhaustion
CVE-2025-13466
CWE-400 Medium
No
No
10.6.0.9, 11.0.0.0 25.11.2025 SB2025112551
SB2026012034
SB2026022521
and 2 more
#VU117276 - Improper input validation
CVE-2025-39971
CWE-20 Low
No
No
10.5.0.21, 10.6.0.9 15.10.2025 SB20251015124
SB2025102476
SB2025102477
and 57 more
#VU116185 - Improper Access Control
CVE-2025-41244
CWE-284 High
No
Exploited
11.0.0.2 30.09.2025 SB2025093024
SB2025093025
SB2025093036
and 21 more
#VU115387 - Use After Free
CVE-2023-53178
CWE-416 Low
No
No
10.5.0.20, 10.6.0.8 16.09.2025 SB20250916124
SB2025101633
SB2025101634
and 30 more
#VU107155 - Use After Free
CVE-2025-31498
CWE-416 High
No
No
10.5.0.19, 10.6.0.7, 10.6.5.0 08.04.2025 SB2025040846
SB2025040925
SB2025040926
and 18 more
#VU101116 - Memory corruption
CVE-2024-53110
CWE-119 Low
No
No
10.6.6.0 03.12.2024 SB2024120321
SB2024121358
SB2024121359
and 24 more
#VU101097 - Missing release of memory after effective lifetime
CVE-2024-53118
CWE-401 Low
No
No
10.6.6.0 03.12.2024 SB2024120304
SB20250115100
SB2025011731
and 18 more
#VU101096 - Missing release of memory after effective lifetime
CVE-2024-53117
CWE-401 Low
No
No
10.6.6.0 03.12.2024 SB2024120303
SB20250115100
SB2025011731
and 18 more
#VU100192 - Error Handling
CVE-2024-50256
CWE-388 Low
No
No
10.6.6.0 10.11.2024 SB2024111036
SB2024112401
SB2024121160
and 58 more
#VU86807 - Out-of-bounds read
CVE-2024-25629
CWE-125 Low
No
No
10.5.0.19, 10.6.0.7, 10.6.5.0 26.02.2024 SB2024022648
SB2024030621
SB2024032954
and 38 more


Showing elements 1 - 20 out of 430