PT-2026-66555 · Ibm · Datapower Gateway 10.5.0+2
CVE-2025-36374
·
Published
2026-07-30
·
Updated
2026-07-30
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H |
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datapower Gateway 10.5.0
Datapower Gateway 10.6.0
Datapower Gateway 10.6Cd