Arbitrary Code Execution Vulnerability in IBM webMethods Integration Products
CVE-2025-36072
What is CVE-2025-36072?
An arbitrarily executed code vulnerability exists in IBM webMethods Integration allowing an authenticated user to manipulate and execute unsafe code due to the deserialization of untrusted object graphs data. This flaw can lead to unauthorized access and potential system compromise. It affects specific versions of the product, making it essential for users to apply the necessary updates and patches provided by IBM.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
webMethods Integration 10.11 <= 10.11_Core_Fix22
webMethods Integration 10.15 <= 10.15_Core_Fix22
webMethods Integration 11.1 <= 11.1_Core_Fix6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved