Arbitrary Code Execution Vulnerability in IBM webMethods Integration Products
CVE-2025-36072
8.8HIGH
What is CVE-2025-36072?
An arbitrarily executed code vulnerability exists in IBM webMethods Integration allowing an authenticated user to manipulate and execute unsafe code due to the deserialization of untrusted object graphs data. This flaw can lead to unauthorized access and potential system compromise. It affects specific versions of the product, making it essential for users to apply the necessary updates and patches provided by IBM.
Affected Version(s)
webMethods Integration 10.11 <= 10.11_Core_Fix22
webMethods Integration 10.15 <= 10.15_Core_Fix22
webMethods Integration 11.1 <= 11.1_Core_Fix6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved