Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rob Maslen

#16804of 53,632
16Total CVSS
Vulnerabilities · 2
High
2
PT-2025-38725
8.8
2025-09-22
Ibm · Webmethods Integration · CVE-2025-36202
**Name of the Vulnerable Software and Affected Versions** IBM webMethods Integration versions 10.15 and 11.1 **Description** An authenticated user with execute Services permissions may be able to execute commands on the system. This is due to improper validation of format string strings received from an external source. **Recommendations** Apply updates to address improper validation of format string strings for IBM webMethods Integration version 10.15. Apply updates to address improper validation of format string strings for IBM webMethods Integration version 11.1.
PT-2025-26178
7.2
2025-06-18
Ibm · Webmethods Integration Server · CVE-2025-36048
**Name of the Vulnerable Software and Affected Versions** IBM webMethods Integration Server versions 10.5 through 10.15 **Description** The issue allows a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. **Recommendations** For versions 10.5 through 10.15, consider restricting the handling of external entities to necessary privileges only, until a proper fix is available. As a temporary workaround, consider disabling the execution of external entities with elevated privileges to minimize the risk of exploitation.