Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now by moving to IBM webMethods Integration Server 12.1 version.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7260932 |
|
Fri, 20 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:webmethods_integration_server:12.0.0:*:*:*:*:*:*:* |
Tue, 17 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Title | IBM webMethods Integration Server is vulnerable to HTML injection | |
| First Time appeared |
Ibm
Ibm webmethods Integration Server |
|
| Weaknesses | CWE-80 | |
| CPEs | cpe:2.3:a:ibm:webmethods_integration_server:12.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm webmethods Integration Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-02-17T21:08:20.351Z
Reserved: 2025-12-08T19:17:32.509Z
Link: CVE-2025-14289
Updated: 2026-02-17T21:08:17.608Z
Status : Analyzed
Published: 2026-02-17T21:22:14.067
Modified: 2026-02-20T21:03:53.983
Link: CVE-2025-14289
No data.
OpenCVE Enrichment
Updated: 2026-02-18T10:33:21Z