IBM webMethods Integration是美国国际商业机器(IBM)公司的一个混合的企业 iPaaS。 IBM webMethods Integration 10.5版本、10.7版本、10.11版本和10.15版本存在安全漏洞,该漏洞源于处理外部实体时权限不当,可能导致权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | webMethods Integration Server | 10.5 |
cpe:2.3:a:softwareag:webmethods:10.5:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-36049 | 8.8 HIGH | IBM webMethods Integration Sever XML external entity injection |
| CVE-2025-1349 | 5.5 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting |
| CVE-2024-54183 | 5.4 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting |
| CVE-2024-54172 | 4.3 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery |
| CVE-2025-1348 | 4.0 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure |
No comments yet