216.73.217.22

CVE-2025-36375

· Published 01/04/2026 23:17 · Modified 01/04/2026 23:17

Labels: CVE-2025-36375 2026-04-01CVE-2025-36375CWE-352[email protected]

Essential information

Published
01/04/2026 23:17
Modified
01/04/2026 23:17
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVSS metrics

Description

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / datapower gateway cpe:2.3:a:ibm:datapower_gateway:10.6.1.0-10.6.5.0:*:*:*:*:*:*:*
ibm / datapower gateway cpe:2.3:a:ibm:datapower_gateway:10.5.0.0-10.5.0.20:*:*:*:*:*:*:*
ibm / datapower gateway cpe:2.3:a:ibm:datapower_gateway:10.6.0.0-10.6.0.8:*:*:*:*:*:*:*

References