Datapower Gateway 1060 IBM Datapower Gateway 1060

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Datapower Gateway 1060.

By the Year

In 2026 there have been 4 vulnerabilities in IBM Datapower Gateway 1060 with an average score of 5.9 out of ten.

Year Vulnerabilities Average Score
2026 4 5.90

It may take a day or so for new Datapower Gateway 1060 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Datapower Gateway 1060 Security Vulnerabilities

IBM DataPower Gateway: Remote DoS via Resource Exhaustion
CVE-2026-12733 7.5 - High - July 30, 2026

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

Allocation of Resources Without Limits or Throttling

IBM DataPower Gateway XXE Vulnerability Exposes Sensitive Data
CVE-2025-36374 5.5 - Medium - July 30, 2026

IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

XXE

IBM DataPower Gateway 10.x CSRF Vulnerability (10.5.0-10.6.5)
CVE-2025-36375 6.5 - Medium - April 01, 2026

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Session Riding

IBM DataPower Gateway <=10.6.5.0 Admin Info Disclosure
CVE-2025-36373 4.1 - Medium - April 01, 2026

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Datapower Gateway 1060 or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe