XML External Entity Injection Vulnerability in IBM DataPower Gateway
CVE-2025-36374
5.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 30 July 2026
What is CVE-2025-36374?
IBM DataPower Gateway is susceptible to an XML External Entity (XXE) injection attack when handling XML data. This vulnerability allows a privileged user to leverage improperly configured XML parsers, potentially leading to the exposure of sensitive information or excessive memory consumption. Mitigation efforts are critical to safeguard against potential exploits.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.21
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.9
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was reported to IBM by Maciej Włodarczyk & Michał Bartoszuk @ STM Cyber.