CVE-2025-14290
Server-Side Request Forgery in IBM webMethods Integration
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | webmethods_integration_server | From 10.15 (inc) to 11.1 (inc) |
| ibm | webmethods_integration_server | From 11.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-918 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-14290 is a server-side request forgery (SSRF) vulnerability in IBM webMethods Integration Server versions 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10. It occurs via the Administration > Publishing > Add subscriber Admin UI page.
This vulnerability allows an authenticated attacker to send unauthorized requests from the affected system, potentially enabling them to perform network enumeration or other malicious activities.
What immediate steps should I take to mitigate this vulnerability?
To mitigate the CVE-2025-14290 vulnerability in IBM webMethods Integration Server, apply the latest core fixes provided by IBM.
- For version 10.15, update to IS_10.15_Core_Fix27 or later.
- For version 11.1, update to IS_11.1_Core_Fix11 or later.
These fixes can be obtained through the IBM webMethods Update Manager. No workarounds are currently available.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can send unauthorized requests from the system, which may lead to network enumeration—gathering information about internal network structure—and facilitate other attacks.
Because the attacker must be authenticated, the risk is limited to users with some level of access, but the impact can still be significant in terms of information disclosure and potential further exploitation.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The provided information does not specify how the CVE-2025-14290 vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.