CVE-2025-14289

IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
References
Link Resource
https://www.ibm.com/support/pages/node/7260932 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:webmethods_integration_server:12.0.0:*:*:*:*:*:*:*

History

20 Feb 2026, 21:03

Type Values Removed Values Added
First Time Ibm webmethods Integration Server
Ibm
References () https://www.ibm.com/support/pages/node/7260932 - () https://www.ibm.com/support/pages/node/7260932 - Vendor Advisory
CPE cpe:2.3:a:ibm:webmethods_integration_server:12.0.0:*:*:*:*:*:*:*

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) IBM webMethods Integration Server 12.0 es vulnerable a la inyección HTML. Un atacante remoto podría inyectar código HTML malicioso que, al ser visto, se ejecutaría en el navegador web de la víctima dentro del contexto de seguridad del sitio de alojamiento.

17 Feb 2026, 21:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 21:22

Updated : 2026-02-20 21:03


NVD link : CVE-2025-14289

Mitre link : CVE-2025-14289

CVE.ORG link : CVE-2025-14289


JSON object : View

Products Affected

ibm

  • webmethods_integration_server
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)