Impact
IBM webMethods Integration Server 11.1 is vulnerable to a remote XML External Entity injection attack that allows an attacker to access confidential data or consume significant memory. The weakness is marked as CWE‑91, indicating improper processing of external XML entities. An attacker who can feed XML to the server could inadvertently leak data or degrade performance, leading to privacy breaches or a denial‑of‑service condition. The primary impact is loss of confidentiality and potential availability disruption.
Affected Systems
Vendors and products affected include IBM webMethods Integration Server version 11.1 (identified as "IBM webMethods Integration Server 11.1"). All builds within the 11.1.0 series and the generic 11.1 release are impacted.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high‑severity from a security standpoint. The EPSS score is not available, so the exact likelihood of exploitation is unclear, but the vulnerability is accessible through normal XML handling paths, implying that a remote attacker could target the server without needing privileged credentials. Because it is not listed in the CISA KEV catalog, it is not confirmed to have known exploits in the wild at the time of this assessment. The expected attack path involves crafting an XML payload that references an external entity, which the server then processes, exposing internal data or consuming the attacker to reach the server’s XML input endpoint, making network accessibility a prerequisite for exploitation.
OpenCVE Enrichment