Loading
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
Use CWE-611, Ibm vendor hub and Webmethods Integration product page to widen CVE-2025-36049 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45076, CVE-2025-36072 and CVE-2024-45075 for nearby disclosures in the same product family.