PT-2026-66555 · Ibm · Datapower Gateway 10.5.0+2

CVE-2025-36374

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-36374

Affected Products

Datapower Gateway 10.5.0
Datapower Gateway 10.6.0
Datapower Gateway 10.6Cd