{"api_version":"1","generated_at":"2026-10-08T21:45:02+00:00","cve":"CVE-2026-13257","urls":{"html":"https://cve.report/CVE-2026-13257","api":"https://cve.report/api/cve/CVE-2026-13257.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-13257","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-13257"},"summary":{"title":"IBM DataPower Gateway Insufficient Verification of Data Authenticity","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-10-08 15:17:48","updated_at":"2026-10-08 20:49:50"},"problem_types":["CWE-345","CWE-345 CWE-345 Insufficient Verification of Data Authenticity"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","name":"https://www.ibm.com/support/pages/node/7289775","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-13257","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13257","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"DataPower Gateway 10.6CD","version":"affected 10.6.1 10.6.6 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"DataPower Gateway 10.6.0","version":"affected 10.6.0.0 10.6.0.10 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"DataPower Gateway 11.0.0","version":"affected 11.0.0.0 11.0.0.2 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"DataPower Gateway 10.5.0","version":"affected 10.5.0.0 10.5.0.22 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly advises upgrading as soon as possible.\n\n\n\nKnown Issue:  DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 \n\nAffected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*"],"product":"DataPower Gateway 10.6CD","vendor":"IBM","versions":[{"lessThanOrEqual":"10.6.6","status":"affected","version":"10.6.1","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.10:*:*:*:*:*:*:*"],"product":"DataPower Gateway 10.6.0","vendor":"IBM","versions":[{"lessThanOrEqual":"10.6.0.10","status":"affected","version":"10.6.0.0","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datapower_gateway_1100:11.0.0.2:*:*:*:*:*:*:*"],"product":"DataPower Gateway 11.0.0","vendor":"IBM","versions":[{"lessThanOrEqual":"11.0.0.2","status":"affected","version":"11.0.0.0","versionType":"semver"}]},{"cpes":["cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.22:*:*:*:*:*:*:*"],"product":"DataPower Gateway 10.5.0","vendor":"IBM","versions":[{"lessThanOrEqual":"10.5.0.22","status":"affected","version":"10.5.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.</p>"}],"value":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-345","description":"CWE-345 Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T14:08:40.802Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7289775"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly advises upgrading as soon as possible.</p><p>Known Issue: <a href=\"https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224\" rel=\"nofollow\">DT499224</a></p><div><table><colgroup><col/><col/></colgroup><tbody><tr><td>Affected Versions</td><td>Fixed in Release</td></tr><tr><td>IBM DataPower Gateway 10.6CD 10.6.1 - 10.6.6</td><td>11.0.0.3</td></tr><tr><td>IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.10</td><td>10.6.0.11</td></tr><tr><td>IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.2</td><td>11.0.0.3</td></tr><tr><td>IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.22</td><td>10.5.0.23</td></tr></tbody></table></div>"}],"value":"IBM strongly advises upgrading as soon as possible.\n\n\n\nKnown Issue:  DT499224 https://www.ibm.com/mysupport/s/defect/aCIgJ000000IiH7/dt499224 \n\nAffected VersionsFixed in ReleaseIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.3IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.1010.6.0.11IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.211.0.0.3IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2210.5.0.23"}],"title":"IBM DataPower Gateway Insufficient Verification of Data Authenticity"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-13257","datePublished":"2026-10-08T14:08:40.802Z","dateReserved":"2026-06-24T20:36:21.020Z","dateUpdated":"2026-10-08T14:08:40.802Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 15:17:48","lastModifiedDate":"2026-10-08 20:49:50","problem_types":["CWE-345","CWE-345 CWE-345 Insufficient Verification of Data Authenticity"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"13257","Ordinal":"1","Title":"IBM DataPower Gateway Insufficient Verification of Data Authenti","CVE":"CVE-2026-13257","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"13257","Ordinal":"1","NoteData":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an authenticated user to forge signature requests due to improper verification of data authenticity.","Type":"Description","Title":"IBM DataPower Gateway Insufficient Verification of Data Authenti"}]}}}