CVE-2025-36375: IBM DataPower Gateway vulnerable to CSRF
Published Mar 30, 2026
·Updated
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
6 affected components
IBM DataPower Gateway 10.6CD<=10.6.1.0 - 10.6.5.0
IBM DataPower Gateway 10.5.0<=10.5.0.0 - 10.5.0.20
IBM DataPower Gateway 10.6.0<=10.6.0.0 - 10.6.0.8
IBM DataPower Gateway>=10.5.0.0<10.5.0.21
IBM DataPower Gateway>=10.6.0.0<10.6.0.9
IBM DataPower Gateway>=10.6.1.0<10.6.6.0
Remediation
Information
Affected Product(s)Fixed in VersionFix linkIBM DataPower Gateway 10.6CD 10.6.1.0 - 10.6.5.010.6.6.0 Installation and Upgrade 10.6.x https://www.ibm.com/docs/en/datapower-gateway/10.6.x IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.810.6.0.9 Installation and Upgrade 10.6.0 https://www.ibm.com/docs/en/datapower-gateway/10.6.0 IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2010.5.0.21 Installation and Upgrade 10.5.0 https://www.ibm.com/docs/en/datapower-gateway/10.5.0
IBM strongly recommends upgrading to a fixed version
Event History
Mar 30, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Apr 1, 2026
CVE Published
via MITRE·10:50 PM
Data Sourced
via MITRE·10:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeaknessAffected Software