Description
IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Published: 2026-09-10
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Exposed sensitive information and resource exhaustion via XXE
Action: Patch immediately
AI Analysis

Impact

IBM webMethods Integration Server 11.1 is vulnerable to a remote XML External Entity injection attack that allows an attacker to access confidential data or consume significant memory. The weakness is marked as CWE‑91, indicating improper processing of external XML entities. An attacker who can feed XML to the server could inadvertently leak data or degrade performance, leading to privacy breaches or a denial‑of‑service condition. The primary impact is loss of confidentiality and potential availability disruption.

Affected Systems

Vendors and products affected include IBM webMethods Integration Server version 11.1 (identified as "IBM webMethods Integration Server 11.1"). All builds within the 11.1.0 series and the generic 11.1 release are impacted.

Risk and Exploitability

The CVSS score of 7.8 classifies this vulnerability as high‑severity from a security standpoint. The EPSS score is not available, so the exact likelihood of exploitation is unclear, but the vulnerability is accessible through normal XML handling paths, implying that a remote attacker could target the server without needing privileged credentials. Because it is not listed in the CISA KEV catalog, it is not confirmed to have known exploits in the wild at the time of this assessment. The expected attack path involves crafting an XML payload that references an external entity, which the server then processes, exposing internal data or consuming the attacker to reach the server’s XML input endpoint, making network accessibility a prerequisite for exploitation.

Generated by OpenCVE AI on September 11, 2026 at 03:54 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective readme document. IS_11.1_Core_Fix14 or later Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software ( https://www.ibm.com/support/pages/node/7232491 )


OpenCVE Recommended Actions

  • Apply the IBM core fix IS_11.1_Core_Fix14 or a later core patch using IBM webMethods Update Manager.
  • Download and install the patch from the IBM webMethods Update Manager portal, following the instructions in the vendor's readme documentation.
  • Review the vendor’s release notes and readme to ensure all related configuration changes are applied and that any remaining vulnerable XML processing components are secured.

Generated by OpenCVE AI on September 11, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Title IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data
First Time appeared Ibm
Ibm webmethods Integration Server
Weaknesses CWE-91
CPEs cpe:2.3:a:ibm:webmethods_integration_server:11.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:webmethods_integration_server:11.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm webmethods Integration Server
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Webmethods Integration Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T22:03:06.079Z

Reserved: 2026-02-10T21:27:08.332Z

Link: CVE-2026-2310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T22:16:55.833

Modified: 2026-09-11T14:56:50.613

Link: CVE-2026-2310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:30:09Z

Weaknesses
  • CWE-91

    XML Injection (aka Blind XPath Injection)