PatchSiren cyber security CVE debrief
CVE-2025-36374 IBM CVE debrief
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. The vulnerability affects IBM DataPower Gateway and could lead to exposure of sensitive information or consumption of memory resources. Defenders should assess exposure and potential impact, focusing on systems and roles handling XML data. The CVE record and NVD entry provide initial details on the vulnerability.
- Vendor
- IBM
- Product
- DataPower Gateway 10.6CD
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-09-29
Who should care
Defenders and administrators handling XML data in IBM DataPower Gateway should assess exposure and potential impact. Roles handling XML data should prioritize verification and mitigation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review system configurations, assess potential impact on sensitive information and memory resources, and plan
Why it matters
Defenders should care about CVE-2025-36374 because it involves an XML external entity injection vulnerability in IBM DataPower Gateway, which could lead to exposure of sensitive information or consumption of memory resources by a privileged user. Roles handling XML data should assess exposure and impact, and prioritize verification and mitigation efforts.
- Potential exposure of sensitive information
- Possible consumption of memory resources
- Need for verification of system exposure and impact
Technical summary
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack. A privileged user could exploit this to expose sensitive information or consume memory resources. The vulnerability is related to XML data processing in IBM DataPower Gateway. Defenders should focus on verifying exposure and assessing potential impact, especially for systems handling XML data.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems and roles handling XML data.
Recommended defensive actions
- Verify if systems handling XML data are exposed to this vulnerability
- Assess potential impact on sensitive information and memory resources
- Review and update XML processing configurations to mitigate XXE attacks
Evidence notes
The CVE record and NVD entry provide initial details on the vulnerability. IBM support pages may offer additional guidance. Evidence is limited to public CVE and NVD details. Defenders should verify system exposure and assess potential impact based on available information. Additional details may be found on IBM support pages.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36374 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36374
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36374 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36374
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7278748
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.