Impact
IBM DataPower Gateway processes XML data and is vulnerable to an XML external entity injection (XXE) attack. An attacker who can inject XML requests could read internal files or network resources, leading to disclosure of sensitive information or depletion of memory resources. The weakness originates from improper validation of external entities in XML parsing, a classic input‑validation flaw (CWE‑611).
Affected Systems
The vulnerability affects IBM DataPower Gateway versions 10.5.0, 10.6.0, and 10.6CD. Affected releases include 10.5.0.0 through 10.5.0.2110.5.0.22, 10.6.0.0 through 10.6.0.910.6.0.10, and 10.6CD 10.6.1 through 10.6.6. Customers running any of these releases should assess whether they receive XML traffic potentially controlled by an attacker.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, yet the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog, further indicating a low probability of current exploitation. The likely attack vector is local privileged users who can submit arbitrary XML to the gateway; no remote attack vector is documented, so the threat is confined to environments where user privileges can reach the DataPower XML engine.
OpenCVE Enrichment