8.8

CVE-2025-36072

IBM webMethods Integration Deserialization

IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmWebmethods Integration Version10.11 Update-
IbmWebmethods Integration Version10.11 Updatecore_fix22
IbmWebmethods Integration Version10.15 Update-
IbmWebmethods Integration Version10.15 Updatecore_fix22
IbmWebmethods Integration Version11.1 Update-
IbmWebmethods Integration Version11.1 Updatecore_fix6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.723
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.