PT-2025-38724 · Ibm · Webmethods Integration

Khanhdlq

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-36037

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM webMethods Integration versions 10.15 and 11.1
Description The software is susceptible to a server-side request forgery (SSRF) condition. An authenticated attacker could potentially leverage this to dispatch unauthorized requests from the system. This may lead to network enumeration or enable further attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-11546
CVE-2025-36037

Affected Products

Webmethods Integration