IBM DataPower Gateway是美国IBM公司的一款安全与集成网关设备。 IBM DataPower Gateway 11.0.0.0版本至11.0.0.1版本、10.5.0.0版本至10.5.0.21版本和10.6.0.0版本至10.6.0.9版本存在竞争条件问题漏洞,该漏洞源于处理内置X-Client-IP头时存在竞争条件,导致请求状态隔离不当,可能造成IP欺骗和其他客户端IP地址泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | DataPower Gateway 10.5.0 | 10.5.0.0≤ 10.5.0.21 |
affected |
| IBM | DataPower Gateway 10.6.0 | 10.6.0.0≤ 10.6.0.9 |
affected |
| IBM | DataPower Gateway 11.0.0 | 11.0.0.0≤ 11.0.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | DataPower Gateway 11.0.0 | 11.0.0.0 ~ 11.0.0.1 |
cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*
|
|
| IBM | DataPower Gateway 10.5.0 | 10.5.0.0 ~ 10.5.0.21 |
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
|
|
| IBM | DataPower Gateway 10.6.0 | 10.6.0.0 ~ 10.6.0.9 |
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-27253 | 10.0 CRITICAL | IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Reviews |
| CVE-2026-16860 | 9.9 CRITICAL | IBM i is Affected By Remote Code Execution Vulnerability [] |
| CVE-2026-16956 | 9.8 CRITICAL | IBM Db2 Mirror for i is vulnerable to OS command injection [] |
| CVE-2026-17218 | 9.8 CRITICAL | IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon [] |
| CVE-2026-17083 | 9.8 CRITICAL | IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
| CVE-2026-17276 | 9.6 CRITICAL | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-18099 | 8.9 HIGH | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-17110 | 8.8 HIGH | IBM i is Affected By Multiple Vulnerabilities in SQL |
| CVE-2026-17082 | 8.8 HIGH | IBM i is Affected By Multiple Vulnerabilities in the Debug Server |
| CVE-2026-18683 | 8.8 HIGH | IBM i is Affected By privilege escalation in Navigator for i |
| CVE-2026-18847 | 8.8 HIGH | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-17417 | 8.8 HIGH | IBM i is Affected By Remote Code Execution Vulnerabilities [, ] |
| CVE-2026-13361 | 8.8 HIGH | IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Executi |
| CVE-2026-13105 | 8.8 HIGH | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-17642 | 8.8 HIGH | IBM i is Affected By Remote Code Execution Vulnerabilities [, ] |
| CVE-2026-18669 | 8.8 HIGH | IBM i is Affected By A Privilege Escalation Vulnerability [] |
| CVE-2026-16906 | 8.8 HIGH | IBM i is Affected By Multiple Vulnerabilities in Domain Name System |
| CVE-2026-16856 | 8.8 HIGH | IBM i is Affected By Multiple Vulnerabilities in Domain Name System |
| CVE-2026-18713 | 8.8 HIGH | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-12004 | 8.7 HIGH | Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Ve |
Showing top 20 of 68 CVEs. View all on vendor page → →
No comments yet