CVE-2026-12733
Awaiting Analysis Awaiting Analysis - Queue

IBM DataPower Gateway Denial of Service Vulnerability

Vulnerability report for CVE-2026-12733, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-31

Assigner: IBM Corporation

Description

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM DataPower Gateway is vulnerable to a denial of service attack due to improper resource limitations. A remote attacker could exploit this to cause the system to become unresponsive or crash by consuming excessive resources.

Impact Analysis

This vulnerability could lead to service disruption, causing downtime for systems relying on IBM DataPower Gateway. It may result in loss of availability for critical applications or data processing tasks.

Compliance Impact

The vulnerability allows a remote attacker to cause a denial of service, which could disrupt services handling sensitive data. This may impact compliance with GDPR by affecting availability of personal data processing systems and HIPAA by interrupting critical healthcare services. However, specific compliance impacts depend on system configuration and data handling practices.

Mitigation Strategies

Apply the latest IBM DataPower Gateway patches or updates provided by IBM to address improper resource limitations. Monitor network traffic for unusual patterns that may indicate a denial of service attempt. Restrict access to the gateway through network segmentation or firewall rules if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12733. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart