CVE-2025-36049

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
References
Link Resource
https://www.ibm.com/support/pages/node/7237146 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:webmethods_integration:10.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:10.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:10.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:10.15:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:linux:-:*:*:*:*:*:*:*

History

13 Aug 2025, 14:08

Type Values Removed Values Added
First Time Linux
Ibm webmethods Integration
Microsoft windows
Linux linux Kernel
Novell
Microsoft
Redhat linux
Apple
Ibm
Novell suse Linux
Redhat
Apple macos
References () https://www.ibm.com/support/pages/node/7237146 - () https://www.ibm.com/support/pages/node/7237146 - Vendor Advisory
CPE cpe:2.3:a:ibm:webmethods_integration:10.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:10.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:10.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:linux:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:10.15:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) IBM webMethods Integration Server 10.5, 10.7, 10.11 y 10.15 es vulnerable a un ataque de inyección de entidad externa (XXE) XML al procesar datos XML. Un atacante remoto autenticado podría aprovechar esta vulnerabilidad para ejecutar comandos arbitrarios.

18 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-18 16:15

Updated : 2025-08-13 14:08


NVD link : CVE-2025-36049

Mitre link : CVE-2025-36049

CVE.ORG link : CVE-2025-36049


JSON object : View

Products Affected

ibm

  • webmethods_integration

novell

  • suse_linux

microsoft

  • windows

redhat

  • linux

linux

  • linux_kernel

apple

  • macos
CWE
CWE-611

Improper Restriction of XML External Entity Reference