IBM webMethods Integration是美国国际商业机器(IBM)公司的一个混合的企业 iPaaS。 IBM webMethods Integration 10.15版本至IS_10.15_Core_Fix2611.1版本和11.1版本至IS_11.1_Core_Fix10版本存在代码问题漏洞,该漏洞源于容易受到服务器端请求伪造攻击,可能导致经过身份验证的攻击者从系统发送未经授权的请求,进而导致网络枚举或促进其他攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | webMethods Integration (on prem) -Integration Server | 10.15≤ IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | webMethods Integration (on prem) -Integration Server | 10.15 ~ IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 |
cpe:2.3:a:ibm:webmethods_integration_on_prem__integration_server:10.15:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3660 | 9.8 CRITICAL | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authentication Byp |
| CVE-2026-8633 | 9.8 CRITICAL | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8855 | 8.1 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8834 | 8.0 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8856 | 7.7 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8854 | 7.5 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8620 | 7.5 HIGH | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by |
| CVE-2026-8850 | 7.5 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-8835 | 7.3 HIGH | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2026-4051 | 7.2 HIGH | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth R |
| CVE-2026-3603 | 7.1 HIGH | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML external entit |
| CVE-2025-36126 | 6.4 MEDIUM | IBM Cognos Analytics is affected by Cross-site scripting. |
| CVE-2026-8852 | 6.2 MEDIUM | IBM HTTP Server is affected by multiple vulnerabilities |
| CVE-2025-13755 | 5.5 MEDIUM | IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase |
| CVE-2025-36148 | 5.4 MEDIUM | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to c |
| CVE-2025-36145 | 5.4 MEDIUM | Multiple Vulnerabilities in watsonx.data |
| CVE-2025-36221 | 5.3 MEDIUM | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2025-36220 | 4.3 MEDIUM | Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops. |
| CVE-2026-9170 | IBM HTTP Server is affected by multiple vulnerabilities |
No comments yet