CVE-2025-36037
- EPSS 0.03%
- Veröffentlicht 22.09.2025 15:17:10
- Zuletzt bearbeitet 03.10.2025 19:12:49
IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other ...
CVE-2025-36202
- EPSS 0.05%
- Veröffentlicht 22.09.2025 15:14:44
- Zuletzt bearbeitet 03.10.2025 19:13:00
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.
CVE-2025-36048
- EPSS 0.13%
- Veröffentlicht 18.06.2025 16:15:27
- Zuletzt bearbeitet 13.08.2025 14:12:38
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.
CVE-2025-36049
- EPSS 0.16%
- Veröffentlicht 18.06.2025 16:15:27
- Zuletzt bearbeitet 13.08.2025 14:08:53
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
CVE-2024-45074
- EPSS 0.24%
- Veröffentlicht 04.09.2024 16:15:08
- Zuletzt bearbeitet 06.09.2024 16:45:32
IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVE-2024-45075
- EPSS 0.16%
- Veröffentlicht 04.09.2024 16:15:08
- Zuletzt bearbeitet 29.09.2025 18:15:30
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
CVE-2024-45076
- EPSS 0.23%
- Veröffentlicht 04.09.2024 16:15:08
- Zuletzt bearbeitet 06.09.2024 16:44:52
IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.