CVE-2025-36375
EUVD-2025-20917601.04.2026, 23:17
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | datapower_gateway | 10.5.0.0 ≤ 𝑥 < 10.5.0.21 |
| ibm | datapower_gateway | 10.6.0.0 ≤ 𝑥 < 10.6.0.9 |
| ibm | datapower_gateway | 10.6.1.0 ≤ 𝑥 < 10.6.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration