Back to database
Schedule49Medium4.9VulnerabilityCVE-2026-14521No patch link observed

CVE-2026-14521 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to…

Published Oct 8, 2026, 01:17 PM UTCIngested 9h agoSource NVD(cve-db)CVE-2026-14521

Description

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
4.9

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

High

Attack Complexity

PR

Low

Privileges Required

UI

None

User Interaction

S

Changed

Scope

C

Low

Confidentiality

I

Low

Integrity

A

None

Availability