CVE-2025-36049: IBM webMethods Integration Sever XML external entity injection
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36049?
CVE-2025-36049 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-36049?
To remediate CVE-2025-36049, upgrade IBM webMethods Integration Server to a patched version that addresses the XML external entity injection issue.
What software versions are affected by CVE-2025-36049?
CVE-2025-36049 affects IBM webMethods Integration Server versions 10.5, 10.7, 10.11, and 10.15.
What type of attack is enabled by CVE-2025-36049?
CVE-2025-36049 enables an XML external entity injection (XXE) attack.
Can a remote attacker exploit CVE-2025-36049?
Yes, a remote authenticated attacker can exploit CVE-2025-36049 to execute arbitrary commands.