Description
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Published: 2026-07-30
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM DataPower Gateway processes XML data and is vulnerable to an XML external entity injection (XXE) attack. An attacker who can inject XML requests could read internal files or network resources, leading to disclosure of sensitive information or depletion of memory resources. The weakness originates from improper validation of external entities in XML parsing, a classic input‑validation flaw (CWE‑611).

Affected Systems

The vulnerability affects IBM DataPower Gateway versions 10.5.0, 10.6.0, and 10.6CD. Affected releases include 10.5.0.0 through 10.5.0.2110.5.0.22, 10.6.0.0 through 10.6.0.910.6.0.10, and 10.6CD 10.6.1 through 10.6.6. Customers running any of these releases should assess whether they receive XML traffic potentially controlled by an attacker.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity, yet the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog, further indicating a low probability of current exploitation. The likely attack vector is local privileged users who can submit arbitrary XML to the gateway; no remote attack vector is documented, so the threat is confined to environments where user privileges can reach the DataPower XML engine.

Generated by OpenCVE AI on August 3, 2026 at 10:37 UTC.

Remediation

Vendor Solution

Affected Product(s)Fixed in ReleaseFix InstructionsIBM DataPower Gateway 10.6CD 10.6.1 - 10.6.611.0.0.2 https://www.ibm.com/docs/en/datapower-gateway/11.0.0?topic=overview-release-notes#relnotes__install__title__1 IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.2110.5.0.22 https://www.ibm.com/docs/en/datapower-gateway/10.5.0?topic=overview-release-notes#relnotes__install__title__1 IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.910.6.0.10 https://www.ibm.com/docs/en/datapower-gateway/10.6.0?topic=overview-release-notes#relnotes__install__title__1 IBM strongly advises upgrading as soon as possible.


OpenCVE Recommended Actions

  • Upgrade IBM DataPower Gateway 10.6CD to 10.6.611.0.0.2 following IBM’s release instructions.
  • Upgrade IBM DataPower Gateway 10.5.0 to 10.5.0.2110.5.0.22 by applying the indicated patches.
  • Upgrade IBM DataPower Gateway 10.6.0 to 10.6.0.910.6.0.10 as directed in IBM’s documentation.

Generated by OpenCVE AI on August 3, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Title IBM DataPower Gateway affected by XML external entity injection
First Time appeared Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1050:10.5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_1060:10.6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway_106cd:10.6.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datapower Gateway 1050
Ibm datapower Gateway 1060
Ibm datapower Gateway 106cd
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Ibm Datapower Gateway 1050 Datapower Gateway 1060 Datapower Gateway 106cd
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T18:49:22.675Z

Reserved: 2025-04-15T21:16:56.325Z

Link: CVE-2025-36374

cve-icon Vulnrichment

Updated: 2026-07-30T18:49:04.115Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T19:16:58.867

Modified: 2026-07-30T19:31:02.643

Link: CVE-2025-36374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference