PT-2026-108010 · Ibm · Datapower Gateway 10.5.0+3

CVE-2026-14905

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-14905

Produtos afetados

Datapower Gateway 10.5.0
Datapower Gateway 10.6.0
Datapower Gateway 10.6Cd
Datapower Gateway 11.0.0