Security Advisory

CVE-2025-36374

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-30 17:55:11
Last updated 2026-07-30 18:49:22
Assigner ibm
CVSS score not scored
State PUBLISHED

Description

IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.