CVE-2025-36202 Details
Description
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.
A remote code execution vulnerability has been identified in IBM webMethods Integration versions 10.15 and 11.1. This issue arises from improper validation of format strings in the 'pub.xslt.transformSerialXML' function, allowing authenticated users with the necessary permissions to execute commands on the system.
Users are advised to upgrade to IBM webMethods Integration IS_10.15_Core_Fix22 or later, or IS_11.1_Core_Fix6 or later. These fixes can be downloaded and installed via the IBM webMethods Update Manager. For more information on how to download webMethods software, please refer to the IBM webMethods Support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7245720 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm webmethods integration | 10.5 11.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | Initial Analysis | [email protected] |
| Sep 22, 2025 | New CVE Received | [email protected] |