CNNVD-202506-2537 Information

CNNVD ID

CNNVD-202506-2537

CVE-2025-36049

  • CNNVD Published: 2025-06-18

Description (Chinese)

IBM webMethods Integration是美国国际商业机器(IBM)公司的一个混合的企业 iPaaS。 IBM webMethods Integration Server 10.5版本、10.7版本、10.11版本和10.15版本存在代码问题漏洞,该漏洞源于XML外部实体注入漏洞,可能导致执行任意命令。

Description (English)

IBM webMethods Information is a hybrid enterprise of the United States International Business Machinery (IBM) iPaas. The IBM webMethods Information Server 10.5, 10.7, 10.11 and 10.15 have code gaps, which stem from gaps in the external XML entities and may lead to arbitrary orders being executed.

Hazard Level

Medium

Vulnerability Type

代码问题

Affected Vendor

国际商业机器

Published

2025-06-18

Last Modified

2026-02-24

References

https://www.ibm.com/support/pages/node/7237146

Patch

https://www.ibm.com/support/pages/node/7237146

Share on: