PT-2025-2365 · Software Ag · Webmethods

Rasime Ekici

·

Published

2025-01-29

·

Updated

2025-04-16

·

CVE-2024-23733

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Software AG webMethods versions 10.15.0 before Core Fix7
Description The issue allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the "/WmAdmin/#/login/" API endpoint.
Recommendations For Software AG webMethods versions 10.15.0 before Core Fix7, consider disabling access to the "/WmAdmin/#/login/" API endpoint until a patch is available. Restrict the use of the username and password variables in this endpoint to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-23733

Affected Products

Webmethods