Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Webmethods Integration Server
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-14290 1 Ibm 1 Webmethods Integration Server 2026-06-01 N/A 5.4 MEDIUM
IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticatedĀ attacker to send unauthorized requests from the system, potentially leading to network enumeration orĀ facilitating other attacks.
CVE-2025-14289 1 Ibm 1 Webmethods Integration Server 2026-02-20 N/A 5.4 MEDIUM
IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hostingĀ site.