CVE 9.3 CRITICAL

ibi WebFOCUS – Unauthenticated RCE Vulnerability_CVE-2025-11548

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Description

A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution

Basic Information

ID CVE-2025-11548
Source tibco
Published Oct 14, 2025 at 16:45
Modified Oct 14, 2025 at 19:15

Affected Product

Vendor ibi
Product WebFOCUS
Version 9.1
Affected Versions ibi WebFOCUS 9.1
ibi WebFOCUS 9.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.