CVE-2025-36373

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.
References
Link Resource
https://www.ibm.com/support/pages/node/7267833 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:continuous_delivery:*:*:*

History

No history.

Information

Published : 2026-04-01 21:16

Updated : 2026-06-17 09:14


NVD link : CVE-2025-36373

Mitre link : CVE-2025-36373

CVE.ORG link : CVE-2025-36373


JSON object : View

Products Affected

ibm

  • datapower_gateway
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

NVD-CWE-noinfo