CVE-2025-36374: IBM DataPower Gateway affected by XML external entity injection
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataPower Gateway 10.5.0to a version that resolves this vulnerability.Fixed in 10.5.0.22 - Upgrade
Upgrade
IBM DataPower Gateway 10.6.0to a version that resolves this vulnerability.Fixed in 10.6.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36374?
The severity of CVE-2025-36374 is classified as medium with a score of 5.5.
How do I fix CVE-2025-36374?
To fix CVE-2025-36374, ensure that the IBM DataPower Gateway is updated to the latest version that addresses this vulnerability.
What impact does CVE-2025-36374 have?
CVE-2025-36374 can allow a privileged user to exploit an XML external entity injection to expose sensitive information or consume memory resources.
Which products are affected by CVE-2025-36374?
CVE-2025-36374 affects IBM DataPower Gateway versions 10.5.0, 10.6.0, and 10.6CD.
What type of attack is associated with CVE-2025-36374?
CVE-2025-36374 is associated with an XML external entity injection (XXE) attack.