CVE-2025-14290
Analyzed Analyzed - Analysis Complete
Server-Side Request Forgery in IBM webMethods Integration

Publication date: 2026-05-26

Last updated on: 2026-06-01

Assigner: IBM Corporation

Description
IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticatedΒ attacker to send unauthorized requests from the system, potentially leading to network enumeration orΒ facilitating other attacks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-06-01
Generated
2026-06-16
AI Q&A
2026-05-26
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm webmethods_integration_server 10.15.0
ibm webmethods_integration_server 11.1.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

To mitigate the CVE-2025-14290 vulnerability in IBM webMethods Integration Server, apply the latest core fixes provided by IBM.

  • For version 10.15, update to IS_10.15_Core_Fix27 or later.
  • For version 11.1, update to IS_11.1_Core_Fix11 or later.

These fixes can be obtained through the IBM webMethods Update Manager. No workarounds are currently available.

Executive Summary

CVE-2025-14290 is a server-side request forgery (SSRF) vulnerability in IBM webMethods Integration Server versions 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10. It occurs via the Administration > Publishing > Add subscriber Admin UI page.

This vulnerability allows an authenticated attacker to send unauthorized requests from the affected system, potentially enabling them to perform network enumeration or other malicious activities.

Impact Analysis

An attacker exploiting this vulnerability can send unauthorized requests from the system, which may lead to network enumerationβ€”gathering information about internal network structureβ€”and facilitate other attacks.

Because the attacker must be authenticated, the risk is limited to users with some level of access, but the impact can still be significant in terms of information disclosure and potential further exploitation.

Compliance Impact

The provided information does not specify how the CVE-2025-14290 vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14290. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart