VYPR
Medium severity4.1NVD Advisory· Published Apr 1, 2026· Updated Apr 6, 2026

CVE-2025-36373

CVE-2025-36373

Description

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.

Affected products

2
  • cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:*range: >=10.5.0.0,<10.5.0.21
    • cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:continuous_delivery:*:*:*range: >=10.6.1.0,<10.6.6.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.