IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.
History

Wed, 18 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Description IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.
Title IBM webMethods Integration Sever code execution
First Time appeared Softwareag
Softwareag webmethods
Weaknesses CWE-250
CPEs cpe:2.3:a:softwareag:webmethods:10.11:*:*:*:*:*:*:*
cpe:2.3:a:softwareag:webmethods:10.15:*:*:*:*:*:*:*
cpe:2.3:a:softwareag:webmethods:10.5:*:*:*:*:*:*:*
cpe:2.3:a:softwareag:webmethods:10.7:*:*:*:*:*:*:*
Vendors & Products Softwareag
Softwareag webmethods
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-06-18T16:04:28.802Z

Updated: 2025-06-18T17:53:01.000Z

Reserved: 2025-04-15T21:16:10.569Z

Link: CVE-2025-36048

cve-icon Vulnrichment

Updated: 2025-06-18T17:49:51.221Z

cve-icon NVD

Status : Received

Published: 2025-06-18T16:15:27.080

Modified: 2025-06-18T16:15:27.080

Link: CVE-2025-36048

cve-icon Redhat

No data.