XML External Entity Injection Vulnerability in IBM webMethods Integration Server
CVE-2026-2310
7.8HIGH
What is CVE-2026-2310?
IBM webMethods Integration Server 11.1 contains a vulnerability that allows attackers to execute XML External Entity Injection (XXE) attacks when processing XML data. This vulnerability can be exploited by a remote attacker, potentially leading to exposure of sensitive information and excessive consumption of memory resources, which poses a significant threat to overall system integrity.
Affected Version(s)
webMethods Integration Server 11.1