EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in IBM DataPower Gateway that could allow remote attackers to execute arbitrary code or disclose sensitive information. These vulnerabilities are considered critical and require immediate attention.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in IBM DataPower Gateway that could allow remote attackers to execute arbitrary code or disclose sensitive information. These vulnerabilities are considered critical and require immediate attention.[emaillocker id="1283"]
CVE-2026-14991 (CVSS 9.8 — Critical): A remote attacker can execute arbitrary code due to an out-of-bounds write.
CVE-2026-15762 (CVSS 9.8 — Critical): It is an out-of-bounds write vulnerability in IBM DataPower Gateway that could allow a remote attacker to execute arbitrary code.
CVE-2026-16340 (CVSS 9.8 — Critical): It is an out-of-bounds write vulnerability in the RFC 2047 encoded-word parser of IBM DataPower Gateway that could allow a remote attacker to execute arbitrary code.
CVE-2026-14990 (CVSS 9.3 — Critical): An unauthenticated user can embed arbitrary JavaScript code in the Web UI, leading to credentials disclosure within a trusted session.
CVE-2026-16159 (CVSS 8.6 — High): It is an out-of-bounds write vulnerability in IBM DataPower Gateway that could allow a remote attacker to disclose sensitive information and cause a denial of service.
CVE-2026-16163 (CVSS 8.6 — High): It is an out-of-bounds write vulnerability in IBM DataPower Gateway that could allow a remote attacker to cause memory corruption.
CVE-2026-15824 (CVSS 8.2 — High): is a heap-based buffer overflow vulnerability in IBM DataPower Gateway that could allow a remote attacker to cause a denial of service.
CVE-2026-15784 (CVSS 8.1 — High): It is an out-of-bounds write vulnerability in IBM DataPower Gateway that could allow a remote attacker to execute arbitrary code.
CVE-2026-15781 (CVSS 8.0 — High): It is a buffer overflow vulnerability in IBM DataPower Gateway that could allow a remote authenticated attacker to execute arbitrary code.
CVE-2026-16181 (CVSS 7.4 — High): It is an improper authorization vulnerability in IBM DataPower Gateway that could allow a remote attacker to bypass security restrictions.
CVE-2026-16177 (CVSS 5.3 — Medium): It is an out-of-bounds read vulnerability in IBM DataPower Gateway that could allow a remote authenticated attacker to obtain sensitive information.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://securityonline.info/ibm-datapower-gateway-vulnerabilities/