CVE-2025-36373

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2026
Last modified:
06/04/2026

Description

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:* 10.5.0.0 (including) 10.5.0.21 (excluding)
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:*:*:*:* 10.6.0.0 (including) 10.6.0.9 (excluding)
cpe:2.3:a:ibm:datapower_gateway:*:*:*:*:continuous_delivery:*:*:* 10.6.1.0 (including) 10.6.6.0 (excluding)


References to Advisories, Solutions, and Tools