PT-2026-108015 · Ibm · Datapower Gateway 10.5.0+3

CVE-2026-14999

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to bypass authentication by forging valid JSON Web Signatures due to improper verification of cryptographic signatures.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-14999

Produtos afetados

Datapower Gateway 10.5.0
Datapower Gateway 10.6.0
Datapower Gateway 10.6Cd
Datapower Gateway 11.0.0