Description
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
Published: 2025-07-07
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM Integration Bus for z/OS. IBM Integration Bus for z/OS 10.1.0.0 - 10.1.0.5 z/OS only   PH65769 Interim Fix for APAR (PH65769) is available to apply to 10.1.0.5 from IBM Fix Central

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-20269 IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
History

Mon, 25 Aug 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm z\/os
CPEs cpe:2.3:a:ibm:integration_bus_for_z\/os:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:integration_bus:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:*
Vendors & Products Ibm integration Bus For Z\/os
Ibm z\/os

Thu, 14 Aug 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm integration Bus For Z\/os
CPEs cpe:2.3:a:ibm:integration_bus_for_z\/os:*:*:*:*:*:*:*:*
Vendors & Products Ibm integration Bus For Z\/os

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00019}

epss

{'score': 0.00024}


Tue, 08 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
Description IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
Title IBM Integration Bus for z/OS code injection
First Time appeared Ibm
Ibm integration Bus
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:integration_bus:10.1.0.5:*:*:*:*:zos:*:*
cpe:2.3:a:ibm:integration_bus:10.1:*:*:*:*:zos:*:*
Vendors & Products Ibm
Ibm integration Bus
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Integration Bus Z\/os
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-26T18:27:55.117Z

Reserved: 2025-04-15T21:16:07.862Z

Link: CVE-2025-36014

cve-icon Vulnrichment

Updated: 2025-07-08T13:49:17.976Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-07T17:15:27.890

Modified: 2025-08-25T02:19:33.600

Link: CVE-2025-36014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses