Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Rob Maslen

#17854of 56,330
16Total CVSS
Vulnerabilities · 2
High
2
PT-2025-38725
8.8
2025-09-22
Ibm · Webmethods Integration · CVE-2025-36202
**Name of the Vulnerable Software and Affected Versions** IBM webMethods Integration versions 10.15 and 11.1 **Description** An authenticated user with execute Services permissions may be able to execute commands on the system. This is due to improper validation of format string strings received from an external source. **Recommendations** Apply updates to address improper validation of format string strings for IBM webMethods Integration version 10.15. Apply updates to address improper validation of format string strings for IBM webMethods Integration version 11.1.
PT-2025-26178
7.2
2025-06-18
Ibm · Webmethods Integration Server · CVE-2025-36048
**Name of the Vulnerable Software and Affected Versions** IBM webMethods Integration Server versions 10.5 through 10.15 **Description** The issue allows a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges. **Recommendations** For versions 10.5 through 10.15, consider restricting the handling of external entities to necessary privileges only, until a proper fix is available. As a temporary workaround, consider disabling the execution of external entities with elevated privileges to minimize the risk of exploitation.