CVE-2026-2310 PUBLISHED

IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data

Assigner: ibm
Reserved: 10.02.2026 Published: 10.09.2026 Updated: 10.09.2026

IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor IBM
Product webMethods Integration Server
Versions
  • Version 11.1 is affected

Solutions

IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective readme document.

IS_11.1_Core_Fix14 or later

Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software ( https://www.ibm.com/support/pages/node/7232491 )

References

Problem Types

  • CWE-91 XML Injection (aka Blind XPath Injection) CWE