XML External Entity Injection Vulnerability in IBM DataPower Gateway
CVE-2025-36374

5.5MEDIUM

What is CVE-2025-36374?

IBM DataPower Gateway is susceptible to an XML External Entity (XXE) injection attack when handling XML data. This vulnerability allows a privileged user to leverage improperly configured XML parsers, potentially leading to the exposure of sensitive information or excessive memory consumption. Mitigation efforts are critical to safeguard against potential exploits.

Affected Version(s)

DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.21

DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.9

DataPower Gateway 10.6CD 10.6.1 <= 10.6.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was reported to IBM by Maciej Włodarczyk &amp; Michał Bartoszuk @ STM Cyber.
.