Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
IBM DataPower Gateway affected by XML external entity injection
CVE-2025-36374
Description
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7278748mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.