8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data.
Basic Information
ID
CVE-2025-36072
Source
ibm
Published
Nov 20, 2025 at 22:09
Affected Product
Vendor
IBM
Product
webMethods Integration
Version
10.11
Affected Versions
IBM webMethods Integration 10.11
IBM webMethods Integration 10.15
IBM webMethods Integration 11.1
IBM webMethods Integration 10.15
IBM webMethods Integration 11.1