Medium severity4.1NVD Advisory· Published Apr 1, 2026· Updated Apr 6, 2026
CVE-2025-36373
CVE-2025-36373
Description
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.
Affected products
2cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*range: >=10.5.0.0,<10.5.0.21
- cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:continuous_delivery:*:*:*range: >=10.6.1.0,<10.6.6.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7267833nvdVendor Advisory
News mentions
0No linked articles in our index yet.