IBM Support

Update packages for DataPower Gateway 10.6.x

Download


Downloadable File

File linkFile sizeFile description
   
   
   
   
   

Abstract

Lists of fixes in IBM DataPower Gateway 10.6.x update packages.

Download Description

Fix packs and firmware images are located in either Fix Central, Passport Advantage, or the Entitled Registry.

In IBM Knowledge Center you can find information about new and changed features, limitations, and restrictions.

Attention: In the next LTS, you cannot modify the browser URL to access the WebGUI.

Security policy update to password management

10.6.2 - New security policy introduced to improve the security posture for password management that uses stronger algorithms. Because of this security improvement, the installation of an earlier firmware version fails and the system starts in failsafe mode. To recover, use the rollback procedure to switch between the current installed version (primary) and the previous installed version (secondary), which is with the flash boot switch command.

The downgrade procedure is for earlier fix packs in the same major release. For firmware images across major releases, which are earlier update packages in the CD stream or an earlier LTS fix pack, you must reinitialize the system. After reinitialization, restore its configuration from the secure backup package that you created before you upgraded the firmware. To reinitialize, use the flash reinitialize command.

For more information, see Firmware management.

Host keys and establishing an SSH session

10.6.2 - The DataPower SSH server now supports ECDSA and ED25519 SSH host keys. After you upgrade, ECDSA and ED25519 keys are generated. After the upgrade, The SSH handshake chooses one of these stronger algorithms over RSA. As a result, you might see a receive a warning about the change to the host identification, which is expected due to the key update. For more information, see Connection after host keys changed.

Important



10.6.6

Release date: 11 December 2025
Last modified: 11 December 2025
Status: Available

APAR
Description
DT419165Add HttpOnly flag on Cookies when secure flag is set
DT419166Improve input validation of login page
DT420234DataPower might restart if ITX DPA file cannot be read
DT423135Login failure from one user might cause intermittent errors for other users
DT423402REST FetchFile action returns 403 when the user is authorized
DT433885Username exposed in login page URL
DT448972New UI: Processing policies with hundreds of rules can fail to load in the editor.
DT449619Edit Web Service Proxy with MQV9+ remote gives HTTP 503
DT449835Some SNMP OIDs are missing
DT450353API call returns 401 error due to deleted API definitions being chosen
DT450554Make GatewayScript engine lightweight
DT451647When viewing certificate details, some details might not be displayed
DT452211DataPower HTTP TLS client might hang if server closes connection during handshake
DT452230Enhance schema validation of operation-switch policy in API YAML
DT453225Ping messages do not indicate success or how many packets failed.
DT453872DataPower might restart when receiving SOAP requests with attachments from API Connect
DT454318JWT Validate action does not get the property value correctly for "request.parameters.*"
DT454655DataPower might restart if AMQP broker disconnects unexpectedly.
DT454673The show running-config command prints output without stopping
DT454833DataPower might reload if resource consumption from the strict rate limit cache persists when the domain is being disabled.
DT456571DataPower might restart when an unresponsive gateway peer triggers an invalid TMS response.
DT457308Console log targets can go down after configuration
DT457315OIDC discovery cannot handle chunked or delayed data streams
DT457316Memory growth when using HTTP Bearer security scheme due to missing URL resource and response payload releases
DT457361Duplicate API registries when processing snapshot
DT457446REST requests to the file store do not enforce depth limit if depth=0
DT457456Reporting interval for dbleak does not work with monitor thresholds
DT457616After modifying extension file, Filestore type gateway extension files disappears
DT457652TypeError during peer enrollment
DT457654Missing references to TLS profile and registry in catalog global and user-defined policies
DT457702DataPower might run out of memory with high inactive memory growth
DT457828Gateway might reload when token management cache provides an invalid or empty response
DT458264Messages might be routed to the wrong queue when an MQ task restarts
DT465802Gateway initialization and updates from APIM may be slow to process when peer members are detected as removed

10.6.5

Release date: 6 October 2025
Last modified: 6 October 2025
Status: Available

APAR
Description
DT419120After change the basic authentication password in APIC Cloud Manager third party oauth provider it is not updated in DataPower
DT419847New UI does not correctly reflect the MQ V9+ GMO setting
DT431976API Connect gateway service does not become operational with too many APIC domains are on same device
DT436301API Connect gateway might restart when new APIs are published while taking traffic
DT436926Wrong captured parameter value when using grouping constructs in the path parameter's pattern keyword
DT437472Show HSM directory in drop down when HSM license enabled
DT438304AAA Custom token AAA info file custom token being improperly updated.
DT439663Two APIs with the same name and different content cause 0x88e00371 error
DT440104Improve performance of RMI GET /mgmt/config with state=1
DT440181File names that APIM generates for an API gateway might be too long (> 255)
DT442595DataPower HTTP/2 server might not honor idle timeout
DT442780In new UI, domain status shows probe not enable after it is enabled
DT442897DataPower service variable var://service/mpgw/response-size only works for POST or PUT requests
DT443431In new UI, web service proxy wizard does not display MQ queue manager references
DT443961Temporary file for Debug Probe is not deleted
DT444257DataPower might exhibit high CPU utilization when connections are in CLOSE_WAIT state.
DT444596UI does not inform user if export was denied due to insufficient permissions
DT444654DataPower might restart if RBM access profile is invalid.
DT446126New UI unable to select Default domain for import when restoring backup.
DT446624Excessive HTTP/2 reset frame rates can cause CPU spin
DT446737DataPower might restart if an XML firewall with a dynamic backend is modified while processing traffic.
DT446757MQMD header's AccountingToken field might have the wrong value
DT446793Missing support to disable parsing form-data parameter
DT446795Analytics service remains in DataPower after unassociating in API Manager
DT447247Corrupt payload to APIGW with Parse Action or DP Service/MPGW with XML processing will reload DataPower
DT447310One down B2B Profile can impact the entire B2B Profile Group.
DT447390DataPower might reload in the low CPU environment
DT447610Missing millisecond and timezone information in DefaultLog property in Probe data
DT447646GatewayScript debugger might restart when using debug-action command
DT447680DataPower upgrade causes missing Internal Scripts and Gateway Peering Sync Failures in APIC Gateway Cluster.
DT447871DataPower might reject LDAP authorization request when pool is full even when reject-on-pool limit is off
DT447961MQ v9+ client does not honor timeout used in the backend MQ URL URL.
DT448113APIs with user registry stop working after DRR
DT448180While using certificate authentication to log in via SSH and using the -n or -t flags. DataPower might restart
DT448465DataPower might restart from an invalid parameter value in MQ URL
DT448470Gateway peering object op-state may not up after un-quiesce the domain
DT448472Gateway peering might not function as expected if the password includes backslashes or whitespace characters.
DT448523DataPower might show linear growth in Gateway peering cache used by the API security token manager resulting in long sync times and throttling of gateway instances consuming too much RAM.
DT449152New UI unable to construct MessageCountMonitor rate limit
DT449315DataPower Gateway might reload when using GatewayScript FS module
DT449434REST management or new UI requests for large backups or exports might fail with the Max node size exceeded message
DT450624Active sessions of a deleted user do not automatically disconnect.
DT451049Network error when the remote server is unstable and GWS uses multiple urlopener APIs
DT451077Add support for a reference to a non-schema object in an API
DT451411New UI not showing directories nested more than 7 layers deep
DT451514Failed to SSH into 10.6.0.6 container images
DT451627Secure backups might fail when many configuration checkpoints are present
DT451718API gateway stylesheet cache not cleared when user registry is deleted
DT452112MQRC 2142 error occurs when no NameValue is present

10.6.4

Release date: 9 June 2025
Last modified: 9 June 2025
Status: Available

APAR
Description
DT418173Automatically recover member catalog snapshot IDs when reading member to peers table
DT421758Secure backup times out due to domain checkpoints
DT422223ebMS2 Ping fails with missing TLS credentials
DT423281GUI might report incorrect error when restarting a domain
DT423400DataPower might experience memory spikes with amp:GetServiceListFromDomainRequest requests. Memory spikes can occur with SOAP dp:get-config requests for nonprivileged users
DT423445DataPower might unexpectedly restart when GatewayScript uses bigint
DT424822In the GUI, importing configuration in the XML format might fail
DT425671DataPower SSH should comply with generalized key type
DT425672In the GUI, cannot save changes to XML threat protection for an XML firewall
DT425698API Connect TLS client profile not removed from configuration after being detached from the catalog
DT425844In the web service proxy wizard, WSRR subscription policy attachments are not displayed on the SLA policy tab
DT426022MQ v9+ handler cannot route messages to the specified queue in ObjectName of MQOD.
DT426460API Connect catalog summary erroneously reports "Cannot write WSDL"
DT426479Improve messages for OAI3 parameter validation
DT431976API Connect gateway service does become operational with too many APIC domains are on same device
DT433729In GUI, the labels for the encrypted and temporary space are swapped in file management
DT433755Cannot flush the stylesheet and document caches from an XML manager
DT433829New UI might not populate the date field with the selected date
DT434382GUI fails to load multi-protocol gateway processing rules that are missing their transform files
DT434412Identification credentials are not deleted after being removed from TLS client profile in API Manager
DT435251DataPower might restart when cleaning up MQ connections
DT435281IMS Connect client fails to send data when segmentation is enabled
DT435551In new UI, flushing the document cache in an XML manager is not working as expected
DT435919DataPower MQ v9+ clients cannot consume messages
DT435974CORS related headers are not included in the invoke response when response is multipart/related Content-Type
DT436180DataPower might restart when a multi-protocol gateway uses OpenTelemetry and AAA with options such as JWT or social login
DT436904Memory spike or out-of-memory during import from a SOAP request
DT438552DataPower SNMP query for SSH known hosts table throws an error if a host is duplicated
DT438921Unable to change expired password using REST management interface
DT444370TLS client profiles might be incorrectly deleted from the API gateway

10.6.3

Release date: 28 March 2025
Last modified: 28 March 2025
Status: Available

APAR
Description
DT433393Down secondary node is not removed from secondaries list in gateway peering cluster status provider
DT433392IBM MQ v9+ queue manager might stop retry connections when network condition is unstable
DT433389Gateway peering group monitoring process is not restarted again after updating cluster-node list
DT426062Configuration sequence might time out when processing large API Connect snapshots
DT425887The OpenTelemetry endpoint does not use the port set with the OpenTelemetry exporter
DT424562Display status of WS-Addressing Reply Point on WS-Addressing Tab
DT424529DataPower might leak memory
DT424525Context variables of the request body and parameters might be null when accessed by set variable policy
DT424500DataPower might reload when refreshing a large API Connect v5c catalog
DT424498CVE-2022-40228 - force user logout when password changed
DT424492DataPower XMI error log is empty in response
DT424198Add assembly-rate-limit defined in plan to plan context
DT424144Gateway might restart if quota-enforcement-server related command is executed after configuration change
DT424137RMI sessions not cleaned up after returning a 403 in response to the request for accessing singleton resource in non-default domain
DT424023Fix the memory Leak in Analytics Endpoint when remove or disable the configuration
DT423985MQMD header is intermittently missing resulting in a receive 2033 error
DT423951Saving changes via UI to locked Ethernet interface claims to be successful but is not
DT423681DataPower MQ Connectivity failure. Messages lost although unit of work is enabled in the queue manager configuration
DT423627Error referencing API Schema object with name greater than 255 characters
DT423625DataPower memory increase while retrieving GatewayScript debug sessions
DT423401IBM MQ v9+ handler fails to process messages with multiple MQRFH2 headers
DT423381API gateway might leak memory when an assembly action output is not sent to message
DT423337DataPower might unexpectedly restart in an MQv9+ handler if the backside times out
DT423284DataPower syslog-tcp log targets might not clean up all connections
DT423126User policies deployed to an API gateway or v5 compatible gateway fail to deploy certificate files
DT423109Kafka hostname validation behavior not matching with the TLS client profile configuration
DT423068When Autocommit is disabled in a Kafka Cluster, DataPower is unable to consume any messages sent to the cluster service
DT422448API Gateway duplication in XPath Rules/Fields on 10.6.0.1
DT422168DataPower SNMP response for dpStatusSSHTrustedHostStatusHost is not correct
DT422157RMI session not closed when query URI is invalid
DT422155Update gateway peering for CVE-2024-12224 and CVE-2024-11738
DT421417DataPower MQ v9+ client creates unbounded FFDC files that cause temporary space depletion
DT420523DataPower might restart when GatewayScript urlopen module tries to send data
DT420373REST Management Interface does not honor field names such as object names using a numerical value that does not begin with 0, expecting only a string
DT420343Requesting an error report might hang and cause a watchdog reload on next configuration change
DT419917API parameter must support maxLength and minLength of type string
DT419163HTTP/2 idle timeout might cause memory loss
DT419032DataPower might watchdog restart while waiting for a TLS connection shutdown alert
DT418613For API Connect Gateway Invoke Assembly the proxy-authorization header is added even when user/password provided in the connection policy are blank
DT418611Support multiple business IDs in Ping eBMS Destination Action
DT418232API Connect LDAP Password might be exposed in logs with debug logging
DT418223DataPower might restart with multiple urlopen calls from a single GatewayScript
DT417697DataPower might leak memory on XMI ObjectStatus calls
DT417089Activity log bytes_received and bytes_sent overflow
DT416807IBM MQ v9+ queue manager of DataPower does not retry connection when SSL related errors (2393 and 2381) occur
DT416800Log files located in nested directories are not appearing on the System Log page

10.6.2

Release date: 13 December 2024
Last modified: 13 December 2024
Status: Available

APAR
Description
IT46468HTTP/2 SHOULD WORK WITH TLS 1.2 AND TLS 1.3 OR WITH ONLY TLS 1.3
IT46594IN NEW UI, THE PING EBMS DESTINATION ACTION IS MISSING
IT46633DATAPOWER MIGHT RESTART WHEN ASYNCHRONOUS GATEWAYSCRIPT WRITES TO OUTPUT AFTER THE CONNECTION IS CLOSED
IT46665THE PROBE SHOULD NOT COLLECT INTERNAL RULES OR ACTIONS
IT46756PREVENT THE DISPLAY OF THE AUTOFILLED PASSWORD FIELD FOR CERTIFICATE DETAILS
IT46760FOR OAUTH PROVIDER, REQUEST BODY PARAMETERS MIGHT NOT BE REDACTED BEFORE THEY ARE SENT TO THE ANALYTICS ENDPOINT
IT46764IN NEW GUI, EDITING THE AAA POLICY SEEMS TO WORK INCORRECTLY
IT46861REMOVE INTERNAL USER SESSIONS FROM THE LIST OF ACTIVE USERS
IT46869IN LDAP XSLT, SPECIAL CHARACTERS ARE NOT RECOGNIZED
IT46875CATALOG UPDATES THAT FAIL TO COMPLETE SUCCESSFULLY MIGHT STILL RETURN SUCCESS
IT46898GATEWAY MIGHT RESTART WHEN RUNNING GATEWAYSCRIPT DURING REPUBLISH
IT46905IN NEW UI, WSP POLICY RULES ARE NOT SHOWN FOR AN OPERATION
IT46918USE OF ELEMENTS WITH THE SAME LOCAL-NAME() RESULT IN FAILURE WITH WSDL FILES THAT ARE SET FOR STRICT CONFORMITY.
IT46946GATEWAY SERVICE MIGHT FAIL TO PROCESS CHANGES FOR A CATALOG THAT CONTAINS OAUTH CONFIGURATIONS
IT46962OVA DATAPOWER PLATFORM DOES NOT ALLOW NTP TO BE SET BY OVF-ENV.XML
IT46984RATE LIMIT HEADERS FOR ASSEMBLY COUNT LIMITS ARE MISSING FOR API REQUEST
IT46992SNI MAPPING DOES NOT UPDATE WITH NEW CERTIFICATE
IT46998API COLLECTION WITH % IN ORGANIZATION NAME OR ID MIGHT CAUSE GATEWAY RESTART
IT47001APIC GATEWAY MIGHT RESTART IF OAUTH REFRESH TOKEN IS MISSING REQUIRED ELEMENTS
IT47006WITHOUT GATEWAY-PEERING CATALOG DATA, EXCEPTION MIGHT NOT BE CAUGHT
IT47007API MANAGER REGISTRY UPDATE SHOULD CLEAR XSLT CACHE FOR NEW AND UPDATED FILES
IT47054WEB SERVICE PROXY WIZARD DISPLAYS (NONE) FOR ALL PROCESSING RULES WHEN NOT USING THE DEFAULT POLICY
IT47059IN NEW GUI, EDITING A FILE IN NESTED DIRECTORY ON AN OBJECT PAGE CAN RETURN AN ERROR
IT47116AUTOMATIC DRR SHOULD RESULT IN THE SAME CONFIGURATION AS A MANUAL DRR
IT47117API GATEWAY MIGHT NOT GET ITS FULL CONFIGURATION AFTER A RESTART
IT47123DATAPOWER MQ CLIENT REPORTS MESSAGE 0X8D200052: THE (XYZ) REQUEST FAILED (2500)
IT47124IN POLICY EDITOR, STYLESHEET PARAMETERS WITHOUT A TYPE DO NOT DISPLAY
IT47158GATEWAY PEERING MONITOR DOES NOT STOP WHEN DOMAIN IS DISABLED OR QUIESCED
IT47183APIC V5C UDP MIGHT THROW UNEXPECTED ERROR FOR A KEY IN THE CONFIGURATION TO IMPORT
IT47184UPDATE DATAPOWER REDIS LIBRARY TO ADDRESS CVES - CVE-2024-31449 & CVE-2024-31228
IT47185GATEWAY MIGHT RESTART IF GATEWAY PEERING IS DOWN DUE TO THE REFERENCED PEERING GROUP BEING DOWN.
IT47186REMOVING GATEWAY-PEERING PRODUCT LINKS CAN RESULT IN UNEXPECTED BEHAVIOR
IT47187API CONNECT GATEWAY EXTENSION CANNOT COMPLETE IF A PREVIOUS EXTENSION CONTAINED AN INVALID EXTENSION
IT47190RATE LIMIT STATUS PROVIDER NOT RESET CORRECTLY
IT47191REPEATEDLY CREATING AND DELETING APIC CATALOGS FROM A SCRIPT CAN CAUSE AN ERROR
IT47193APIC GRAPHIQL EDITOR DOES NOT UNDERSTAND NEW OPTIONS
IT47227APIC V5C UDP POLICY DELETE MIGHT LEAVE ORPHANED OBJECTS
IT47228B2B GATEWAY MIGHT RESTART WHEN AN ERROR OCCURS IN A ONE-WAY PULL TO AN INBOUND GATEWAY
IT47231APIC PROCESSING LARGE EXTENSIONS IN WEBHOOKS MIGHT USE LARGE AMOUNT OF MEMORY
IT47239DATAPOWER MIGHT RESTART IF AMQP BROKER IS MODIFIED WHILE PROCESSING TRAFFIC
IT47240API GATEWAY INCORRECTLY REJECTS INTEGERS WITH EXPONENTS AS INCORRECT PARAMETERS
IT47242API GATEWAY INCORRECTLY REJECTS FLOATING POINT NUMBER WITH EXPONENT AS INCORRECT PARAMETER
IT47257APIC PARAMETER VALIDATION ERROR SHOULD RETURN HTTP 400 RESPONSE CODE
IT47258OUTBOUND SNI SETTINGS FOR A DATAPOWER MQ CLIENT MIGHT NOT BE APPLIED AFTER THE CONFIGURATION CHANGE
IT47304DATAPOWER MIGHT RESTART WHEN ADDING A GATEWAY-PEERING INSTANCE TO A GATEWAY-PEERING GROUP
IT47386DATAPOWER GATEWAY MIGHT HANG AND RESTART WHEN PROCESSING HIGH RATES OF HTTP/2 TRAFFIC
IT47394HIGH SEVERITY VULNERABILITY IN MQ (CVE-2024-25016)
IT47395ADDRESS FALSE POSITIVE RESULTS FROM VULNERABILITY SCAN

10.6.1

Release date: 25 September 2024
Last modified: 25 September 2024
Status: Available

APAR
Description
IT44640DATAPOWER GATEWAY PEERING CACHE STATUS CAN CAUSE WATCHDOG RESTART
IT44814DATAPOWER SNMP SERVICE MIGHT CAUSE A WATCHDOG RELOAD
IT46718UPDATE SERVER SUBSCRIPTION WHEN ORG AND CAT NAME CHANGE IN AN API COLLECTION
IT46836DATAPOWER RELOAD OCCURS WHEN ATTEMPTING TO PROCESS AN EMPTY OAUTH TOKEN
IT46867APIC GATEWAY SERVICE ERROR SHOULD TRIGGER CATALOG REFRESH
IT46868UI DOES NOT SHOW NEWLY UPLOADED FILE IN APPLICATION DOMAIN
IT46896FROM AN OBJECT CONFIGURATION, THE 'SHOW' COMMAND WITH AN EXTRA SPACE CAUSES A RESTART
IT46897GATEWAY MIGHT RESTART WHEN MODIFYING GATEWAY PEERING OBJECT TO CHANGE LOCAL ADDRESS

Change history
Last modified: 6 October 2025

  • 11 December 2025: Created fix list for 10.6.6 CD release.
  • 6 October 2025: Created fix list for 10.6.5 CD release.
  • 9 June 2025: Created fix list for 10.6.4 CD release.
  • 28 March 2025: Created fix list for 10.6.3 CD release.
  • 13 December 2024: Created fix list for 10.6.2 CD release.
  • 25 September 2024: Created fix list for 10.6.1 CD release.

Off

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"ARM Category":[{"code":"a8m50000000L0rqAAC","label":"DataPower"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.6.1;10.6.2;10.6.3;10.6.4;10.6.5;10.6.6"}]

Problems (APARS) fixed
IT44640; IT44814; IT46718; IT46836; IT46867; IT46868; IT46896; IT46897; IT46468; IT46594; IT46633; IT46665; IT46756; IT46760; IT46764; IT46861; IT46869; IT46875; IT46898; IT46905; IT46918; IT46946; IT46962; IT46984; IT46992; IT46998; IT47001; IT47006; IT47007; IT47054; IT47059; IT47116; IT47117; IT47123; IT47124; IT47158; IT47183; IT47184; IT47185; IT47186; IT47187; IT47190; IT47191; IT47193; IT47227; IT47228; IT47231; IT47239; IT47240; IT47242; IT47257; IT47258; IT47304; IT47386; IT47394; IT47395; DT433393; DT433392; DT433389; DT426062; DT425887; DT424562; DT424529; DT424525; DT424500; DT424498; DT424492; DT424198; DT424144; DT424137; DT424023; DT423985; DT423951; DT423681; DT423627; DT423625; DT423401; DT423381; DT423337; DT423284; DT423126; DT423109; DT423068; DT422448; DT422168; DT422157; DT422155; DT421417; DT420523; DT420373; DT420343; DT419917; DT419163; DT419032; DT418613; DT418611; DT418232; DT418223; DT417697; DT417089; DT416807; DT416800; DT418173; DT421758; DT422223; DT423281; DT423400; DT423445; DT424822; DT425671; DT425672; DT425698; DT425844; DT426022; DT426460; DT426479; DT431976; DT433729; DT433755; DT433829; DT434382; DT434412; DT435251; DT435281; DT435551; DT435919; DT435974; DT436180; DT436904; DT438552; DT444370; DT438921; DT419120; DT419847; DT431976; DT436301; DT436926; DT437472; DT438304; DT439663; DT440104; DT440181; DT442595; DT442780; DT442897; DT443431; DT443961; DT444257; DT444596; DT444654; DT446126; DT446624; DT446737; DT446757; DT446793; DT446795; DT447247; DT447310; DT447390; DT447610; DT447646; DT447680; DT447871; DT447961; DT448113; DT448180; DT448465; DT448470; DT448472; DT448523; DT449152; DT449315; DT449434; DT450624; DT451049; DT451077; DT451411; DT451514; DT451627; DT451718; DT452112; DT419165; DT419166; DT420234; DT423135; DT423402; DT433885; DT448972; DT449619; DT449835; DT450554; DT451647; DT452211; DT452230; DT453225; DT453872; DT454318; DT454655; DT454673; DT454833; DT456571; DT457308; DT457315; DT457316; DT457361; DT457446; DT457456; DT457616; DT457652; DT457654; DT457702; DT457828; DT450353; DT458264; DT465802;

Document Information

Modified date:
23 March 2026

UID

ibm17166786