CVE-2025-36072

8.8

IBM · webMethods Integration

IBM webMethods Integration is vulnerable to arbitrary code execution due to insecure deserialization of untrusted data by an authenticated user.

Executive summary

A critical deserialization vulnerability in IBM webMethods Integration allows authenticated users to execute arbitrary code on the underlying system.

Vulnerability

The flaw resides in the handling of untrusted object graphs during deserialization. An authenticated attacker can leverage this weakness to achieve remote code execution on the host server.

Business impact

Successful exploitation of this vulnerability results in full system compromise, as the attacker can execute arbitrary commands with the privileges of the application. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to complete loss of confidentiality, integrity, and availability of the integration platform and connected backend systems.

Remediation

Immediate Action: Apply the vendor-provided core fixes via the IBM webMethods Update Manager: update to IS_10.11_Core_Fix23, IS_10.15_Core_Fix23, or IS_11.1_Core_Fix7 depending on your specific version.

Proactive Monitoring: Review system access logs for suspicious administrative activity or unusual serialized object traffic originating from authenticated user accounts.

Compensating Controls: Restrict access to the integration management interfaces to trusted internal networks only, and ensure that all user accounts have the principle of least privilege applied.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Organizations utilizing the affected versions of IBM webMethods Integration must prioritize the application of the specified core fixes. Because this vulnerability allows for arbitrary code execution upon authentication, it poses a significant threat to the security of the entire integration architecture and should be addressed during the next available maintenance window.

More IBM CVEs

Sources