PT-2026-22805 · Ibm · Webmethods Api Management+1

CVE-2026-2606

·

Publicado

2026-03-03

·

Atualizado

2026-03-05

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM webMethods API Gateway (on-prem) versions 10.11 through 10.11 Fix3210.15 to 10.15 Fix2711.1 to 11.1 Fix7 IBM webMethods API Management (on-prem) versions 10.11 through 10.11 Fix3210.15 to 10.15 Fix2711.1 to 11.1 Fix7
Description The software does not properly validate user-supplied input provided to the url parameter on the /createapi API endpoint. An attacker can manipulate this parameter to utilize a file:// URI schema instead of the expected https:// schema, potentially allowing unauthorized access to arbitrary files on the underlying server file system.
Recommendations IBM webMethods API Gateway version 10.11 through 10.11 Fix3210.15 should be updated. IBM webMethods API Gateway version 10.15 Fix2711.1 should be updated. IBM webMethods API Gateway version 11.1 Fix7 should be updated. IBM webMethods API Management version 10.11 through 10.11 Fix3210.15 should be updated. IBM webMethods API Management version 10.15 Fix2711.1 should be updated. IBM webMethods API Management version 11.1 Fix7 should be updated.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2606

Produtos afetados

Webmethods Api Gateway
Webmethods Api Management