Junglewise Threat Intelligence

CVE-2025-14290: IBM webMethods Integration Server SSRF in Add Subscriber page

CVE-2025-14290 · Severity: medium · CVSS 5.4 · Published 2026-05-26

Executive brief

IBM webMethods Integration Server, a platform used for connecting disparate software applications and data sources, is vulnerable to a security flaw in its administration interface. An authenticated user could trick the server into making unauthorized requests to internal or external systems. This could allow an attacker to map out private internal networks or access sensitive information that is not intended to be public.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the 'Administration > Publishing > Add subscriber' page of the IBM webMethods Integration Server Admin UI. The vulnerability is caused by improper validation of user-supplied URLs, which allows an authenticated attacker with network access to the management interface to force the server to initiate requests to arbitrary destinations. This can be leveraged for internal network scanning, port enumeration, or interacting with internal services that are otherwise unreachable from the outside. The issue affects versions 10.15 and 11.1 and is resolved in IS_10.15_Core_Fix27 and IS_11.1_Core_Fix11.

Affected products

  • IBM webMethods Integration Server 10.15 through IS_10.15_Core_Fix26; 11.1 through IS_11.1_Core_Fix10

Timeline

  • 2026-05-20: disclosed: Initial publication by IBM
  • 2026-05-26: advisory: NVD publication date

References

Related threats