Vulnerability Details CVE-2025-36049
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15
is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2025-36049
-
cpe:2.3:a:ibm:webmethods_integration:10.11
-
cpe:2.3:a:ibm:webmethods_integration:10.15
-
cpe:2.3:a:ibm:webmethods_integration:10.5
-
cpe:2.3:a:ibm:webmethods_integration:10.7
-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-
-
cpe:2.3:o:novell:suse_linux:-
-