<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>DataPower Gateway (11.0.0.0-11.0.0.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/datapower-gateway-11.0.0.0-11.0.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 15:09:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/datapower-gateway-11.0.0.0-11.0.0.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site Scripting Vulnerability in IBM DataPower Gateway</title><link>https://feed.craftedsignal.io/briefs/2026-10-ibm-datapower-xss/</link><pubDate>Thu, 08 Oct 2026 15:09:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ibm-datapower-xss/</guid><description>IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 contain a reflected cross-site scripting (XSS) vulnerability allowing unauthenticated remote attackers to execute arbitrary JavaScript in the Web UI.</description><content:encoded><![CDATA[<p>IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 are affected by a cross-site scripting (XSS) vulnerability within the product's Web UI. The vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript code into the web interface. Because the gateway interface processes user input without sufficient sanitization, an attacker can execute code in the context of an authenticated user's session. This could result in unauthorized administrative actions, sensitive information disclosure, or credential theft by intercepting session tokens. This vulnerability is critical for organizations relying on the DataPower Gateway for API management and security, as a compromise of the administrative interface undermines the security posture of the protected backend services.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the execution of arbitrary JavaScript within the session of an authenticated user, such as an administrator. Potential consequences include the exfiltration of session cookies, modification of gateway configurations, and unauthorized access to managed API traffic. All deployments of IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 are at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and infrastructure teams:</p>
<ul>
<li>Upgrade all instances of IBM DataPower Gateway to a version beyond 10.6.0.10 immediately.</li>
<li>Until patching is possible, restrict access to the DataPower Web UI management interface to trusted IP addresses using network-level access control lists (ACLs).</li>
<li>Monitor administrative audit logs for unusual access patterns or modifications performed in the Web UI.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>patch-management</category></item></channel></rss>