CVE-2025-36048: IBM webMethods Integration Sever code execution
Published Jun 18, 2025
·Updated
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.
Affected Software
10 affected components
IBM webMethods Integration Server>=10.5<=10.15
All of the following
Any of the following
IBM webMethods Integration=10.5
IBM webMethods Integration=10.7
IBM webMethods Integration=10.11
IBM webMethods Integration=10.15
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Novell SUSE Linux
redhat Linux
Remediation
Information
IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective fix readme document.
IS_10.5_Core_Fix29 or later
IS_10.7_Core_Fix23 or later
IS_10.11_Core_Fix11 or later
IS_10.15_Core_Fix14 or later
Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software
Event History
Jun 18, 2025
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-36048?
CVE-2025-36048 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-36048?
To address CVE-2025-36048, update IBM webMethods Integration Server to the latest version that resolves privilege escalation issues.
3
What versions of IBM webMethods Integration Server are affected by CVE-2025-36048?
CVE-2025-36048 affects IBM webMethods Integration Server versions 10.5, 10.7, 10.11, and 10.15.
4
What type of vulnerability is CVE-2025-36048?
CVE-2025-36048 is a privilege escalation vulnerability caused by unnecessary privileges during the handling of external entities.
5
Who is impacted by CVE-2025-36048?
Privileged users of IBM webMethods Integration Server are at risk of potential privilege escalation due to CVE-2025-36048.