CVE-2025-36202

IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.
References
Link Resource
https://www.ibm.com/support/pages/node/7245720 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:webmethods_integration:10.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:11.1:*:*:*:*:*:*:*

History

03 Oct 2025, 19:13

Type Values Removed Values Added
First Time Ibm
Ibm webmethods Integration
CPE cpe:2.3:a:ibm:webmethods_integration:10.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration:11.1:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7245720 - () https://www.ibm.com/support/pages/node/7245720 - Vendor Advisory

22 Sep 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 16:15

Updated : 2025-10-03 19:13


NVD link : CVE-2025-36202

Mitre link : CVE-2025-36202

CVE.ORG link : CVE-2025-36202


JSON object : View

Products Affected

ibm

  • webmethods_integration
CWE
CWE-134

Use of Externally-Controlled Format String