CVE-2025-36373: IBM Datapower Gateway

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.

Affected products

  • IBM Datapower Gateway: from 10.5.0.0, before 10.5.0.21 (fixed in 10.5.0.21); from 10.6.0.0, before 10.6.0.9 (fixed in 10.6.0.9); from 10.6.1.0, before 10.6.6.0 (fixed in 10.6.6.0)

Published 2026-04-01. Last modified 2026-06-17.