PT-2026-22805 · Ibm · Webmethods Api Management+1
CVE-2026-2606
·
Publicado
2026-03-03
·
Atualizado
2026-03-05
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM webMethods API Gateway (on-prem) versions 10.11 through 10.11 Fix3210.15 to 10.15 Fix2711.1 to 11.1 Fix7
IBM webMethods API Management (on-prem) versions 10.11 through 10.11 Fix3210.15 to 10.15 Fix2711.1 to 11.1 Fix7
Description
The software does not properly validate user-supplied input provided to the
url parameter on the /createapi API endpoint. An attacker can manipulate this parameter to utilize a file:// URI schema instead of the expected https:// schema, potentially allowing unauthorized access to arbitrary files on the underlying server file system.Recommendations
IBM webMethods API Gateway version 10.11 through 10.11 Fix3210.15 should be updated.
IBM webMethods API Gateway version 10.15 Fix2711.1 should be updated.
IBM webMethods API Gateway version 11.1 Fix7 should be updated.
IBM webMethods API Management version 10.11 through 10.11 Fix3210.15 should be updated.
IBM webMethods API Management version 10.15 Fix2711.1 should be updated.
IBM webMethods API Management version 11.1 Fix7 should be updated.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webmethods Api Gateway
Webmethods Api Management