Project Subscriptions
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective fix readme document. IS_10.15_Core_Fix27 or later IS_11.1_Core_Fix11 or later Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software https://www.ibm.com/support/pages/node/7232491
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7273550 |
|
Tue, 26 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm webmethods Integration On Prem Integration Server
|
|
| Vendors & Products |
Ibm webmethods Integration On Prem Integration Server
|
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Title | IBM webMethods Integration Sever is vulnerable to server-side request forgery | |
| First Time appeared |
Ibm
Ibm webmethods Integration On Prem Integration Server |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ibm:webmethods_integration_on_prem__integration_server:10.15.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:webmethods_integration_on_prem__integration_server:10.15:*:*:*:*:*:*:* cpe:2.3:a:ibm:webmethods_integration_on_prem__integration_server:is_10.15_core_fix2611.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm webmethods Integration On Prem Integration Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-05-26T18:40:31.423Z
Reserved: 2025-12-08T19:17:35.305Z
Link: CVE-2025-14290
No data.
Status : Received
Published: 2026-05-26T17:16:28.417
Modified: 2026-05-26T17:16:28.417
Link: CVE-2025-14290
No data.
OpenCVE Enrichment
Updated: 2026-05-26T18:30:12Z