Product
IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 contain a reflected cross-site scripting (XSS) vulnerability allowing unauthenticated remote attackers to execute arbitrary JavaScript in the Web UI.