PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36374 IBM CVE debrief

IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. The vulnerability affects IBM DataPower Gateway and could lead to exposure of sensitive information or consumption of memory resources. Defenders should assess exposure and potential impact, focusing on systems and roles handling XML data. The CVE record and NVD entry provide initial details on the vulnerability.

Vendor
IBM
Product
DataPower Gateway 10.6CD
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-09-29
Advisory published
2026-07-30
Advisory updated
2026-09-29

Who should care

Defenders and administrators handling XML data in IBM DataPower Gateway should assess exposure and potential impact. Roles handling XML data should prioritize verification and mitigation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review system configurations, assess potential impact on sensitive information and memory resources, and plan

Why it matters

Defenders should care about CVE-2025-36374 because it involves an XML external entity injection vulnerability in IBM DataPower Gateway, which could lead to exposure of sensitive information or consumption of memory resources by a privileged user. Roles handling XML data should assess exposure and impact, and prioritize verification and mitigation efforts.

  • Potential exposure of sensitive information
  • Possible consumption of memory resources
  • Need for verification of system exposure and impact

Technical summary

IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack. A privileged user could exploit this to expose sensitive information or consume memory resources. The vulnerability is related to XML data processing in IBM DataPower Gateway. Defenders should focus on verifying exposure and assessing potential impact, especially for systems handling XML data.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems and roles handling XML data.

Recommended defensive actions

  • Verify if systems handling XML data are exposed to this vulnerability
  • Assess potential impact on sensitive information and memory resources
  • Review and update XML processing configurations to mitigate XXE attacks

Evidence notes

The CVE record and NVD entry provide initial details on the vulnerability. IBM support pages may offer additional guidance. Evidence is limited to public CVE and NVD details. Defenders should verify system exposure and assess potential impact based on available information. Additional details may be found on IBM support pages.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36374 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36374

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36374 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36374

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.