{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/datapower-gateway-10.6.0.0-10.6.0.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:datapower_gateway:10.6.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-14990"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DataPower Gateway (10.6.0.0-10.6.0.10)","DataPower Gateway (10.5.0.0-10.5.0.22, 10.6.0.0-10.6.0.10, 10.6.1-10.6.6, 11.0.0.0-11.0.0.2)","DataPower Gateway (11.0.0.0-11.0.0.2)"],"_cs_severities":["critical"],"_cs_tags":["xss","web-vulnerability","patch-management"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 are affected by a cross-site scripting (XSS) vulnerability within the product's Web UI. The vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript code into the web interface. Because the gateway interface processes user input without sufficient sanitization, an attacker can execute code in the context of an authenticated user's session. This could result in unauthorized administrative actions, sensitive information disclosure, or credential theft by intercepting session tokens. This vulnerability is critical for organizations relying on the DataPower Gateway for API management and security, as a compromise of the administrative interface undermines the security posture of the protected backend services.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript within the session of an authenticated user, such as an administrator. Potential consequences include the exfiltration of session cookies, modification of gateway configurations, and unauthorized access to managed API traffic. All deployments of IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of IBM DataPower Gateway to a version beyond 10.6.0.10 immediately.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, restrict access to the DataPower Web UI management interface to trusted IP addresses using network-level access control lists (ACLs).\u003c/li\u003e\n\u003cli\u003eMonitor administrative audit logs for unusual access patterns or modifications performed in the Web UI.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T15:11:11Z","date_published":"2026-10-08T15:09:55Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ibm-datapower-xss/","summary":"IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 contain a reflected cross-site scripting (XSS) vulnerability allowing unauthenticated remote attackers to execute arbitrary JavaScript in the Web UI.","title":"Cross-Site Scripting Vulnerability in IBM DataPower Gateway","url":"https://feed.craftedsignal.io/briefs/2026-10-ibm-datapower-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - DataPower Gateway (10.6.0.0-10.6.0.10)","version":"https://jsonfeed.org/version/1.1"}