IBM webMethods Integration是美国国际商业机器(IBM)公司的一个混合的企业 iPaaS。 IBM webMethods Integration Server 10.5版本、10.7版本、10.11版本和10.15版本存在代码问题漏洞,该漏洞源于XML外部实体注入漏洞,可能导致执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | webMethods Integration Server | 10.5 |
cpe:2.3:a:softwareag:webmethods:10.5:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-36048 | 7.2 HIGH | IBM webMethods Integration Sever code execution |
| CVE-2025-1349 | 5.5 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting |
| CVE-2024-54183 | 5.4 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting |
| CVE-2024-54172 | 4.3 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site request forgery |
| CVE-2025-1348 | 4.0 MEDIUM | IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure |
No comments yet