Junglewise Threat Intelligence

CVE-2025-36374: IBM DataPower Gateway XML external entity injection

CVE-2025-36374 · Severity: medium · CVSS 5.5 · Published 2026-07-30

Executive brief

IBM DataPower Gateway, a security and integration platform for mobile, web, and API workloads, is vulnerable to an XML processing flaw. A user with high-level administrative privileges could exploit this to access sensitive internal information or cause a denial-of-service by exhausting system memory. While the risk is mitigated by the requirement for administrative access, an exploit could still impact the availability of critical business services and expose internal data.

Technical details

IBM DataPower Gateway is vulnerable to an XML External Entity (XXE) injection (CWE-611) due to improper restriction of XML external entity references during XML data processing. The vulnerability is reachable over the network but requires high privileges (PR:H) to exploit. An attacker with these credentials can submit a specially crafted XML document containing malicious external entity references. Successful exploitation allows the attacker to read local files (information disclosure) or trigger excessive memory consumption, leading to a denial-of-service (DoS) condition. IBM has released patches for affected versions 10.5.0, 10.6.0, and 10.6CD.

Affected products

  • IBM DataPower Gateway 10.6CD 10.6.1 - 10.6.6
  • IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.21
  • IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.9

Timeline

  • 2026-07-01: disclosed: Initial publication by IBM
  • 2026-07-01: patched: Fixes released in versions 11.0.0.2, 10.5.0.22, and 10.6.0.10
  • 2026-07-30: advisory: NVD publication date

References

Related threats