← Back

CVE-2025-36375

nvd nist
Published: Apr 1, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Affected (3)

1 product
Datapower Gateway
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 10.5.0.0 to 10.5.0.21
From 10.6.0.0 to 10.6.0.9
From 10.6.1.0 to 10.6.6.0

References (1)

Source: psirt@us.ibm.com
Vendor Advisory

Timeline

No history available yet.