IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
2025-06-18T16:15:27.233
2025-08-13T14:08:53.837
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | webmethods_integration | 10.5 | Yes |
| Application | ibm | webmethods_integration | 10.7 | Yes |
| Application | ibm | webmethods_integration | 10.11 | Yes |
| Application | ibm | webmethods_integration | 10.15 | Yes |
| Operating System | apple | macos | - | No |
| Operating System | linux | linux_kernel | - | No |
| Operating System | microsoft | windows | - | No |
| Operating System | novell | suse_linux | - | No |
| Operating System | redhat | linux | - | No |