Executive brief
IBM webMethods Integration Server is a middleware platform used to integrate business applications and data across enterprises. An XML external entity (XXE) injection vulnerability in version 11.1 allows remote attackers to extract sensitive data or exhaust server memory resources when the system processes malicious XML files, potentially compromising confidential business information or disrupting operations.
Technical details
This is an XML external entity (XXE) injection vulnerability (CWE-91) in IBM webMethods Integration Server's XML processing functionality. The vulnerability allows a remote attacker to send specially crafted XML data that is processed by the server without proper validation of external entity declarations. By exploiting this, an attacker can read arbitrary files from the server, access internal network resources, or trigger denial-of-service conditions through billion laughs or similar XML expansion attacks. The CVSS 3.1 vector indicates local attack vector with low attack complexity and low privileges required. Patches are available via IBM webMethods Update Manager (Core Fix 14 or later for version 11.1).
Affected products
- IBM webMethods Integration Server 11.1
Timeline
- 2026-09-08: disclosed