IBM webMethods API Gateway是美国国际商业机器(IBM)公司的一个接口网关。 IBM webMethods API Gateway 10.11至10.11_Fix3210.15版本、10.15至10.15_Fix2711.1版本和11.1至11.1_Fix7版本存在路径遍历漏洞,该漏洞源于未能正确验证用户提供给/createapi端点url参数的输入,可能导致攻击者修改参数使用file:// URI方案,从而对底层服务器文件系统进行未经授权的任意文件读取访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | webMethods API Gateway (on-prem) | 10.11 ~ 10.11_Fix32 |
cpe:2.3:a:ibm:webmethods_api_gateway_on_prem:10.11:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-1567 | 7.1 HIGH | IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vu |
| CVE-2025-14604 | 6.6 MEDIUM | The following vulnerabilities, which may affect IBM Storage Scale when a directory has a s |
| CVE-2025-13616 | 6.5 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to sensitive information leak due to HTTP re |
| CVE-2025-13686 | 6.3 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime e |
| CVE-2025-13687 | 6.3 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime e |
| CVE-2025-13688 | 6.3 MEDIUM | DataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime e |
| CVE-2025-36364 | 6.2 MEDIUM | IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request que |
| CVE-2025-13490 | 5.9 MEDIUM | IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime op |
| CVE-2025-36363 | 5.9 MEDIUM | IBM DevOps Plan is vulnerable to Excessive Authentication Attempts |
| CVE-2025-13734 | 5.4 MEDIUM | IBM Engineering Requirements Management DOORS Next could allow an authenticated user to ac |
| CVE-2025-14480 | 5.1 MEDIUM | IBM Aspera faspio Gateway 1.3.7 has addressed a vulnerability affected by weak cryptograph |
| CVE-2025-14923 | 4.7 MEDIUM | IBM WebSphere Application Server Liberty could provide weaker than expected security |
| CVE-2026-1265 | 4.3 MEDIUM | IBM InfoSphere Information Server is vulnerable due to sensitive information written to a |
| CVE-2025-14456 | IBM MQ Appliance uses weaker than expected cryptographic algorithms | |
| CVE-2026-1713 | IBM MQ is affected by an authority vulnerablility |
No comments yet