CVE-2026-12733: IBM DataPower Gateway affected by denial of service
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataPower Gatewayto a version that resolves this vulnerability.Fixed in 10.5.0.2110.5.0.22
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit the issue over the network. The CVSS vector indicates that no privileges or user interaction are required.
What is the expected impact of a successful attack?
Successful exploitation can cause a denial of service by exhausting or otherwise improperly consuming resources. The provided CVSS information indicates availability impact only, with no stated confidentiality or integrity impact.
Which DataPower Gateway releases are identified as affected?
The listed affected software includes IBM DataPower Gateway 10.5.0, 10.6.0, 10.6CD, and 11.0.0, as well as IBM DataPower Gateway generally.