Download
Downloadable File
| File link | File size | File description |
|---|---|---|
Abstract
Lists of fixes in IBM DataPower Gateway 10.6.x update packages.
Download Description
Fix packs and firmware images are located in either Fix Central, Passport Advantage, or the Entitled Registry.
In IBM Knowledge Center you can find information about new and changed features, limitations, and restrictions.
- For new features, see What's new.
- For changes, see What's changed.
- For limitations and restrictions, see the Known limitations and restrictions.
Attention: In the next LTS, you cannot modify the browser URL to access the WebGUI.
Security policy update to password management
10.6.2 - New security policy introduced to improve the security posture for password management that uses stronger algorithms. Because of this security improvement, the installation of an earlier firmware version fails and the system starts in failsafe mode. To recover, use the rollback procedure to switch between the current installed version (primary) and the previous installed version (secondary), which is with the flash boot switch command.
The downgrade procedure is for earlier fix packs in the same major release. For firmware images across major releases, which are earlier update packages in the CD stream or an earlier LTS fix pack, you must reinitialize the system. After reinitialization, restore its configuration from the secure backup package that you created before you upgraded the firmware. To reinitialize, use the flash reinitialize command.
For more information, see Firmware management.
Host keys and establishing an SSH session
10.6.2 - The DataPower SSH server now supports ECDSA and ED25519 SSH host keys. After you upgrade, ECDSA and ED25519 keys are generated. After the upgrade, The SSH handshake chooses one of these stronger algorithms over RSA. As a result, you might see a receive a warning about the change to the host identification, which is expected due to the key update. For more information, see Connection after host keys changed.
Important
- Before you install any fix pack or firmware image, review DataPower® Knowledge Collection on firmware updates.
- For more information about how to download DataPower® fix packs, see Fix download method.
- To download from Fix Central, go to the Fix Central.
- To download from Passport Advantage, go to the Passport Advantage Online for customers.
- 10.6.6 Includes new features
- 10.6.5 Includes new features
- 10.6.4 Includes new features
- 10.6.3 Includes new features
- 10.6.2 Includes new features
- 10.6.1 Includes new features and all APARs in 10.6.0.1
10.6.6
Release date: 11 December 2025
Last modified: 11 December 2025
Status: Available
APAR | Description |
| DT419165 | Add HttpOnly flag on Cookies when secure flag is set |
| DT419166 | Improve input validation of login page |
| DT420234 | DataPower might restart if ITX DPA file cannot be read |
| DT423135 | Login failure from one user might cause intermittent errors for other users |
| DT423402 | REST FetchFile action returns 403 when the user is authorized |
| DT433885 | Username exposed in login page URL |
| DT448972 | New UI: Processing policies with hundreds of rules can fail to load in the editor. |
| DT449619 | Edit Web Service Proxy with MQV9+ remote gives HTTP 503 |
| DT449835 | Some SNMP OIDs are missing |
| DT450353 | API call returns 401 error due to deleted API definitions being chosen |
| DT450554 | Make GatewayScript engine lightweight |
| DT451647 | When viewing certificate details, some details might not be displayed |
| DT452211 | DataPower HTTP TLS client might hang if server closes connection during handshake |
| DT452230 | Enhance schema validation of operation-switch policy in API YAML |
| DT453225 | Ping messages do not indicate success or how many packets failed. |
| DT453872 | DataPower might restart when receiving SOAP requests with attachments from API Connect |
| DT454318 | JWT Validate action does not get the property value correctly for "request.parameters.*" |
| DT454655 | DataPower might restart if AMQP broker disconnects unexpectedly. |
| DT454673 | The show running-config command prints output without stopping |
| DT454833 | DataPower might reload if resource consumption from the strict rate limit cache persists when the domain is being disabled. |
| DT456571 | DataPower might restart when an unresponsive gateway peer triggers an invalid TMS response. |
| DT457308 | Console log targets can go down after configuration |
| DT457315 | OIDC discovery cannot handle chunked or delayed data streams |
| DT457316 | Memory growth when using HTTP Bearer security scheme due to missing URL resource and response payload releases |
| DT457361 | Duplicate API registries when processing snapshot |
| DT457446 | REST requests to the file store do not enforce depth limit if depth=0 |
| DT457456 | Reporting interval for dbleak does not work with monitor thresholds |
| DT457616 | After modifying extension file, Filestore type gateway extension files disappears |
| DT457652 | TypeError during peer enrollment |
| DT457654 | Missing references to TLS profile and registry in catalog global and user-defined policies |
| DT457702 | DataPower might run out of memory with high inactive memory growth |
| DT457828 | Gateway might reload when token management cache provides an invalid or empty response |
| DT458264 | Messages might be routed to the wrong queue when an MQ task restarts |
| DT465802 | Gateway initialization and updates from APIM may be slow to process when peer members are detected as removed |
10.6.5
Release date: 6 October 2025
Last modified: 6 October 2025
Status: Available
APAR | Description |
| DT419120 | After change the basic authentication password in APIC Cloud Manager third party oauth provider it is not updated in DataPower |
| DT419847 | New UI does not correctly reflect the MQ V9+ GMO setting |
| DT431976 | API Connect gateway service does not become operational with too many APIC domains are on same device |
| DT436301 | API Connect gateway might restart when new APIs are published while taking traffic |
| DT436926 | Wrong captured parameter value when using grouping constructs in the path parameter's pattern keyword |
| DT437472 | Show HSM directory in drop down when HSM license enabled |
| DT438304 | AAA Custom token AAA info file custom token being improperly updated. |
| DT439663 | Two APIs with the same name and different content cause 0x88e00371 error |
| DT440104 | Improve performance of RMI GET /mgmt/config with state=1 |
| DT440181 | File names that APIM generates for an API gateway might be too long (> 255) |
| DT442595 | DataPower HTTP/2 server might not honor idle timeout |
| DT442780 | In new UI, domain status shows probe not enable after it is enabled |
| DT442897 | DataPower service variable var://service/mpgw/response-size only works for POST or PUT requests |
| DT443431 | In new UI, web service proxy wizard does not display MQ queue manager references |
| DT443961 | Temporary file for Debug Probe is not deleted |
| DT444257 | DataPower might exhibit high CPU utilization when connections are in CLOSE_WAIT state. |
| DT444596 | UI does not inform user if export was denied due to insufficient permissions |
| DT444654 | DataPower might restart if RBM access profile is invalid. |
| DT446126 | New UI unable to select Default domain for import when restoring backup. |
| DT446624 | Excessive HTTP/2 reset frame rates can cause CPU spin |
| DT446737 | DataPower might restart if an XML firewall with a dynamic backend is modified while processing traffic. |
| DT446757 | MQMD header's AccountingToken field might have the wrong value |
| DT446793 | Missing support to disable parsing form-data parameter |
| DT446795 | Analytics service remains in DataPower after unassociating in API Manager |
| DT447247 | Corrupt payload to APIGW with Parse Action or DP Service/MPGW with XML processing will reload DataPower |
| DT447310 | One down B2B Profile can impact the entire B2B Profile Group. |
| DT447390 | DataPower might reload in the low CPU environment |
| DT447610 | Missing millisecond and timezone information in DefaultLog property in Probe data |
| DT447646 | GatewayScript debugger might restart when using debug-action command |
| DT447680 | DataPower upgrade causes missing Internal Scripts and Gateway Peering Sync Failures in APIC Gateway Cluster. |
| DT447871 | DataPower might reject LDAP authorization request when pool is full even when reject-on-pool limit is off |
| DT447961 | MQ v9+ client does not honor timeout used in the backend MQ URL URL. |
| DT448113 | APIs with user registry stop working after DRR |
| DT448180 | While using certificate authentication to log in via SSH and using the -n or -t flags. DataPower might restart |
| DT448465 | DataPower might restart from an invalid parameter value in MQ URL |
| DT448470 | Gateway peering object op-state may not up after un-quiesce the domain |
| DT448472 | Gateway peering might not function as expected if the password includes backslashes or whitespace characters. |
| DT448523 | DataPower might show linear growth in Gateway peering cache used by the API security token manager resulting in long sync times and throttling of gateway instances consuming too much RAM. |
| DT449152 | New UI unable to construct MessageCountMonitor rate limit |
| DT449315 | DataPower Gateway might reload when using GatewayScript FS module |
| DT449434 | REST management or new UI requests for large backups or exports might fail with the Max node size exceeded message |
| DT450624 | Active sessions of a deleted user do not automatically disconnect. |
| DT451049 | Network error when the remote server is unstable and GWS uses multiple urlopener APIs |
| DT451077 | Add support for a reference to a non-schema object in an API |
| DT451411 | New UI not showing directories nested more than 7 layers deep |
| DT451514 | Failed to SSH into 10.6.0.6 container images |
| DT451627 | Secure backups might fail when many configuration checkpoints are present |
| DT451718 | API gateway stylesheet cache not cleared when user registry is deleted |
| DT452112 | MQRC 2142 error occurs when no NameValue is present |
10.6.4
Release date: 9 June 2025
Last modified: 9 June 2025
Status: Available
APAR | Description |
| DT418173 | Automatically recover member catalog snapshot IDs when reading member to peers table |
| DT421758 | Secure backup times out due to domain checkpoints |
| DT422223 | ebMS2 Ping fails with missing TLS credentials |
| DT423281 | GUI might report incorrect error when restarting a domain |
| DT423400 | DataPower might experience memory spikes with amp:GetServiceListFromDomainRequest requests. Memory spikes can occur with SOAP dp:get-config requests for nonprivileged users |
| DT423445 | DataPower might unexpectedly restart when GatewayScript uses bigint |
| DT424822 | In the GUI, importing configuration in the XML format might fail |
| DT425671 | DataPower SSH should comply with generalized key type |
| DT425672 | In the GUI, cannot save changes to XML threat protection for an XML firewall |
| DT425698 | API Connect TLS client profile not removed from configuration after being detached from the catalog |
| DT425844 | In the web service proxy wizard, WSRR subscription policy attachments are not displayed on the SLA policy tab |
| DT426022 | MQ v9+ handler cannot route messages to the specified queue in ObjectName of MQOD. |
| DT426460 | API Connect catalog summary erroneously reports "Cannot write WSDL" |
| DT426479 | Improve messages for OAI3 parameter validation |
| DT431976 | API Connect gateway service does become operational with too many APIC domains are on same device |
| DT433729 | In GUI, the labels for the encrypted and temporary space are swapped in file management |
| DT433755 | Cannot flush the stylesheet and document caches from an XML manager |
| DT433829 | New UI might not populate the date field with the selected date |
| DT434382 | GUI fails to load multi-protocol gateway processing rules that are missing their transform files |
| DT434412 | Identification credentials are not deleted after being removed from TLS client profile in API Manager |
| DT435251 | DataPower might restart when cleaning up MQ connections |
| DT435281 | IMS Connect client fails to send data when segmentation is enabled |
| DT435551 | In new UI, flushing the document cache in an XML manager is not working as expected |
| DT435919 | DataPower MQ v9+ clients cannot consume messages |
| DT435974 | CORS related headers are not included in the invoke response when response is multipart/related Content-Type |
| DT436180 | DataPower might restart when a multi-protocol gateway uses OpenTelemetry and AAA with options such as JWT or social login |
| DT436904 | Memory spike or out-of-memory during import from a SOAP request |
| DT438552 | DataPower SNMP query for SSH known hosts table throws an error if a host is duplicated |
| DT438921 | Unable to change expired password using REST management interface |
| DT444370 | TLS client profiles might be incorrectly deleted from the API gateway |
10.6.3
Release date: 28 March 2025
Last modified: 28 March 2025
Status: Available
APAR | Description |
| DT433393 | Down secondary node is not removed from secondaries list in gateway peering cluster status provider |
| DT433392 | IBM MQ v9+ queue manager might stop retry connections when network condition is unstable |
| DT433389 | Gateway peering group monitoring process is not restarted again after updating cluster-node list |
| DT426062 | Configuration sequence might time out when processing large API Connect snapshots |
| DT425887 | The OpenTelemetry endpoint does not use the port set with the OpenTelemetry exporter |
| DT424562 | Display status of WS-Addressing Reply Point on WS-Addressing Tab |
| DT424529 | DataPower might leak memory |
| DT424525 | Context variables of the request body and parameters might be null when accessed by set variable policy |
| DT424500 | DataPower might reload when refreshing a large API Connect v5c catalog |
| DT424498 | CVE-2022-40228 - force user logout when password changed |
| DT424492 | DataPower XMI error log is empty in response |
| DT424198 | Add assembly-rate-limit defined in plan to plan context |
| DT424144 | Gateway might restart if quota-enforcement-server related command is executed after configuration change |
| DT424137 | RMI sessions not cleaned up after returning a 403 in response to the request for accessing singleton resource in non-default domain |
| DT424023 | Fix the memory Leak in Analytics Endpoint when remove or disable the configuration |
| DT423985 | MQMD header is intermittently missing resulting in a receive 2033 error |
| DT423951 | Saving changes via UI to locked Ethernet interface claims to be successful but is not |
| DT423681 | DataPower MQ Connectivity failure. Messages lost although unit of work is enabled in the queue manager configuration |
| DT423627 | Error referencing API Schema object with name greater than 255 characters |
| DT423625 | DataPower memory increase while retrieving GatewayScript debug sessions |
| DT423401 | IBM MQ v9+ handler fails to process messages with multiple MQRFH2 headers |
| DT423381 | API gateway might leak memory when an assembly action output is not sent to message |
| DT423337 | DataPower might unexpectedly restart in an MQv9+ handler if the backside times out |
| DT423284 | DataPower syslog-tcp log targets might not clean up all connections |
| DT423126 | User policies deployed to an API gateway or v5 compatible gateway fail to deploy certificate files |
| DT423109 | Kafka hostname validation behavior not matching with the TLS client profile configuration |
| DT423068 | When Autocommit is disabled in a Kafka Cluster, DataPower is unable to consume any messages sent to the cluster service |
| DT422448 | API Gateway duplication in XPath Rules/Fields on 10.6.0.1 |
| DT422168 | DataPower SNMP response for dpStatusSSHTrustedHostStatusHost is not correct |
| DT422157 | RMI session not closed when query URI is invalid |
| DT422155 | Update gateway peering for CVE-2024-12224 and CVE-2024-11738 |
| DT421417 | DataPower MQ v9+ client creates unbounded FFDC files that cause temporary space depletion |
| DT420523 | DataPower might restart when GatewayScript urlopen module tries to send data |
| DT420373 | REST Management Interface does not honor field names such as object names using a numerical value that does not begin with 0, expecting only a string |
| DT420343 | Requesting an error report might hang and cause a watchdog reload on next configuration change |
| DT419917 | API parameter must support maxLength and minLength of type string |
| DT419163 | HTTP/2 idle timeout might cause memory loss |
| DT419032 | DataPower might watchdog restart while waiting for a TLS connection shutdown alert |
| DT418613 | For API Connect Gateway Invoke Assembly the proxy-authorization header is added even when user/password provided in the connection policy are blank |
| DT418611 | Support multiple business IDs in Ping eBMS Destination Action |
| DT418232 | API Connect LDAP Password might be exposed in logs with debug logging |
| DT418223 | DataPower might restart with multiple urlopen calls from a single GatewayScript |
| DT417697 | DataPower might leak memory on XMI ObjectStatus calls |
| DT417089 | Activity log bytes_received and bytes_sent overflow |
| DT416807 | IBM MQ v9+ queue manager of DataPower does not retry connection when SSL related errors (2393 and 2381) occur |
| DT416800 | Log files located in nested directories are not appearing on the System Log page |
10.6.2
Release date: 13 December 2024
Last modified: 13 December 2024
Status: Available
APAR | Description |
| IT46468 | HTTP/2 SHOULD WORK WITH TLS 1.2 AND TLS 1.3 OR WITH ONLY TLS 1.3 |
| IT46594 | IN NEW UI, THE PING EBMS DESTINATION ACTION IS MISSING |
| IT46633 | DATAPOWER MIGHT RESTART WHEN ASYNCHRONOUS GATEWAYSCRIPT WRITES TO OUTPUT AFTER THE CONNECTION IS CLOSED |
| IT46665 | THE PROBE SHOULD NOT COLLECT INTERNAL RULES OR ACTIONS |
| IT46756 | PREVENT THE DISPLAY OF THE AUTOFILLED PASSWORD FIELD FOR CERTIFICATE DETAILS |
| IT46760 | FOR OAUTH PROVIDER, REQUEST BODY PARAMETERS MIGHT NOT BE REDACTED BEFORE THEY ARE SENT TO THE ANALYTICS ENDPOINT |
| IT46764 | IN NEW GUI, EDITING THE AAA POLICY SEEMS TO WORK INCORRECTLY |
| IT46861 | REMOVE INTERNAL USER SESSIONS FROM THE LIST OF ACTIVE USERS |
| IT46869 | IN LDAP XSLT, SPECIAL CHARACTERS ARE NOT RECOGNIZED |
| IT46875 | CATALOG UPDATES THAT FAIL TO COMPLETE SUCCESSFULLY MIGHT STILL RETURN SUCCESS |
| IT46898 | GATEWAY MIGHT RESTART WHEN RUNNING GATEWAYSCRIPT DURING REPUBLISH |
| IT46905 | IN NEW UI, WSP POLICY RULES ARE NOT SHOWN FOR AN OPERATION |
| IT46918 | USE OF ELEMENTS WITH THE SAME LOCAL-NAME() RESULT IN FAILURE WITH WSDL FILES THAT ARE SET FOR STRICT CONFORMITY. |
| IT46946 | GATEWAY SERVICE MIGHT FAIL TO PROCESS CHANGES FOR A CATALOG THAT CONTAINS OAUTH CONFIGURATIONS |
| IT46962 | OVA DATAPOWER PLATFORM DOES NOT ALLOW NTP TO BE SET BY OVF-ENV.XML |
| IT46984 | RATE LIMIT HEADERS FOR ASSEMBLY COUNT LIMITS ARE MISSING FOR API REQUEST |
| IT46992 | SNI MAPPING DOES NOT UPDATE WITH NEW CERTIFICATE |
| IT46998 | API COLLECTION WITH % IN ORGANIZATION NAME OR ID MIGHT CAUSE GATEWAY RESTART |
| IT47001 | APIC GATEWAY MIGHT RESTART IF OAUTH REFRESH TOKEN IS MISSING REQUIRED ELEMENTS |
| IT47006 | WITHOUT GATEWAY-PEERING CATALOG DATA, EXCEPTION MIGHT NOT BE CAUGHT |
| IT47007 | API MANAGER REGISTRY UPDATE SHOULD CLEAR XSLT CACHE FOR NEW AND UPDATED FILES |
| IT47054 | WEB SERVICE PROXY WIZARD DISPLAYS (NONE) FOR ALL PROCESSING RULES WHEN NOT USING THE DEFAULT POLICY |
| IT47059 | IN NEW GUI, EDITING A FILE IN NESTED DIRECTORY ON AN OBJECT PAGE CAN RETURN AN ERROR |
| IT47116 | AUTOMATIC DRR SHOULD RESULT IN THE SAME CONFIGURATION AS A MANUAL DRR |
| IT47117 | API GATEWAY MIGHT NOT GET ITS FULL CONFIGURATION AFTER A RESTART |
| IT47123 | DATAPOWER MQ CLIENT REPORTS MESSAGE 0X8D200052: THE (XYZ) REQUEST FAILED (2500) |
| IT47124 | IN POLICY EDITOR, STYLESHEET PARAMETERS WITHOUT A TYPE DO NOT DISPLAY |
| IT47158 | GATEWAY PEERING MONITOR DOES NOT STOP WHEN DOMAIN IS DISABLED OR QUIESCED |
| IT47183 | APIC V5C UDP MIGHT THROW UNEXPECTED ERROR FOR A KEY IN THE CONFIGURATION TO IMPORT |
| IT47184 | UPDATE DATAPOWER REDIS LIBRARY TO ADDRESS CVES - CVE-2024-31449 & CVE-2024-31228 |
| IT47185 | GATEWAY MIGHT RESTART IF GATEWAY PEERING IS DOWN DUE TO THE REFERENCED PEERING GROUP BEING DOWN. |
| IT47186 | REMOVING GATEWAY-PEERING PRODUCT LINKS CAN RESULT IN UNEXPECTED BEHAVIOR |
| IT47187 | API CONNECT GATEWAY EXTENSION CANNOT COMPLETE IF A PREVIOUS EXTENSION CONTAINED AN INVALID EXTENSION |
| IT47190 | RATE LIMIT STATUS PROVIDER NOT RESET CORRECTLY |
| IT47191 | REPEATEDLY CREATING AND DELETING APIC CATALOGS FROM A SCRIPT CAN CAUSE AN ERROR |
| IT47193 | APIC GRAPHIQL EDITOR DOES NOT UNDERSTAND NEW OPTIONS |
| IT47227 | APIC V5C UDP POLICY DELETE MIGHT LEAVE ORPHANED OBJECTS |
| IT47228 | B2B GATEWAY MIGHT RESTART WHEN AN ERROR OCCURS IN A ONE-WAY PULL TO AN INBOUND GATEWAY |
| IT47231 | APIC PROCESSING LARGE EXTENSIONS IN WEBHOOKS MIGHT USE LARGE AMOUNT OF MEMORY |
| IT47239 | DATAPOWER MIGHT RESTART IF AMQP BROKER IS MODIFIED WHILE PROCESSING TRAFFIC |
| IT47240 | API GATEWAY INCORRECTLY REJECTS INTEGERS WITH EXPONENTS AS INCORRECT PARAMETERS |
| IT47242 | API GATEWAY INCORRECTLY REJECTS FLOATING POINT NUMBER WITH EXPONENT AS INCORRECT PARAMETER |
| IT47257 | APIC PARAMETER VALIDATION ERROR SHOULD RETURN HTTP 400 RESPONSE CODE |
| IT47258 | OUTBOUND SNI SETTINGS FOR A DATAPOWER MQ CLIENT MIGHT NOT BE APPLIED AFTER THE CONFIGURATION CHANGE |
| IT47304 | DATAPOWER MIGHT RESTART WHEN ADDING A GATEWAY-PEERING INSTANCE TO A GATEWAY-PEERING GROUP |
| IT47386 | DATAPOWER GATEWAY MIGHT HANG AND RESTART WHEN PROCESSING HIGH RATES OF HTTP/2 TRAFFIC |
| IT47394 | HIGH SEVERITY VULNERABILITY IN MQ (CVE-2024-25016) |
| IT47395 | ADDRESS FALSE POSITIVE RESULTS FROM VULNERABILITY SCAN |
10.6.1
Release date: 25 September 2024
Last modified: 25 September 2024
Status: Available
APAR | Description |
| IT44640 | DATAPOWER GATEWAY PEERING CACHE STATUS CAN CAUSE WATCHDOG RESTART |
| IT44814 | DATAPOWER SNMP SERVICE MIGHT CAUSE A WATCHDOG RELOAD |
| IT46718 | UPDATE SERVER SUBSCRIPTION WHEN ORG AND CAT NAME CHANGE IN AN API COLLECTION |
| IT46836 | DATAPOWER RELOAD OCCURS WHEN ATTEMPTING TO PROCESS AN EMPTY OAUTH TOKEN |
| IT46867 | APIC GATEWAY SERVICE ERROR SHOULD TRIGGER CATALOG REFRESH |
| IT46868 | UI DOES NOT SHOW NEWLY UPLOADED FILE IN APPLICATION DOMAIN |
| IT46896 | FROM AN OBJECT CONFIGURATION, THE 'SHOW' COMMAND WITH AN EXTRA SPACE CAUSES A RESTART |
| IT46897 | GATEWAY MIGHT RESTART WHEN MODIFYING GATEWAY PEERING OBJECT TO CHANGE LOCAL ADDRESS |
Change history
Last modified: 6 October 2025
- 11 December 2025: Created fix list for 10.6.6 CD release.
- 6 October 2025: Created fix list for 10.6.5 CD release.
- 9 June 2025: Created fix list for 10.6.4 CD release.
- 28 March 2025: Created fix list for 10.6.3 CD release.
- 13 December 2024: Created fix list for 10.6.2 CD release.
- 25 September 2024: Created fix list for 10.6.1 CD release.
Document Location
Worldwide
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
23 March 2026
UID
ibm17166786