CVE-2025-14290
Received Received - Intake
Server-Side Request Forgery in IBM webMethods Integration

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: IBM Corporation

Description
IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-05-26
AI Q&A
2026-05-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm webmethods_integration_server From 10.15 (inc) to 11.1 (inc)
ibm webmethods_integration_server From 11.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-14290 is a server-side request forgery (SSRF) vulnerability in IBM webMethods Integration Server versions 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10. It occurs via the Administration > Publishing > Add subscriber Admin UI page.

This vulnerability allows an authenticated attacker to send unauthorized requests from the affected system, potentially enabling them to perform network enumeration or other malicious activities.


What immediate steps should I take to mitigate this vulnerability?

To mitigate the CVE-2025-14290 vulnerability in IBM webMethods Integration Server, apply the latest core fixes provided by IBM.

  • For version 10.15, update to IS_10.15_Core_Fix27 or later.
  • For version 11.1, update to IS_11.1_Core_Fix11 or later.

These fixes can be obtained through the IBM webMethods Update Manager. No workarounds are currently available.


How can this vulnerability impact me? :

An attacker exploiting this vulnerability can send unauthorized requests from the system, which may lead to network enumeration—gathering information about internal network structure—and facilitate other attacks.

Because the attacker must be authenticated, the risk is limited to users with some level of access, but the impact can still be significant in terms of information disclosure and potential further exploitation.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The provided information does not specify how the CVE-2025-14290 vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart