IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM webMethods Integration could disclose sensitive user information in server responses.

Project Subscriptions

Vendors Products
Webmethods Integration On Prem Integration Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective readme document. IS_10.15_Core_Fix25 or later IS_11.1_Core_Fix9 or later Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software ( https://www.ibm.com/support/pages/node/7232491) https://www.ibm.com/support/pages/node/7232491%29


Workaround

No workaround given by the vendor.

History

Thu, 05 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Description IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM webMethods Integration could disclose sensitive user information in server responses.
Title IBM webMethods Integration Sever is affected by
First Time appeared Ibm
Ibm webmethods Integration On Prem Integration Server
Weaknesses CWE-497
CPEs cpe:2.3:a:ibm:webmethods_integration_on_prem___integration_server:10.15.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration_on_prem___integration_server:10.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration_on_prem___integration_server:is_10.15_core_fix2411.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm webmethods Integration On Prem Integration Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-05T14:43:18.651Z

Reserved: 2025-12-05T19:31:47.566Z

Link: CVE-2025-14150

cve-icon Vulnrichment

Updated: 2026-02-05T14:42:51.612Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-05T14:16:04.090

Modified: 2026-02-05T14:57:20.563

Link: CVE-2025-14150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses