8.8

CVE-2025-36072

IBM webMethods Integration Deserialization

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Webmethods Integration Version 10.11 Update -
Ibm ≫ Webmethods Integration Version 10.11 Update core_fix22
Ibm ≫ Webmethods Integration Version 10.15 Update -
Ibm ≫ Webmethods Integration Version 10.15 Update core_fix22
Ibm ≫ Webmethods Integration Version 11.1 Update -
Ibm ≫ Webmethods Integration Version 11.1 Update core_fix6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.384
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.ibm.com/support/pages/node/7252090
Vendor Advisory