Metrics
Affected Vendors & Products
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective readme document. IS_11.1_Core_Fix14 or later Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software ( https://www.ibm.com/support/pages/node/7232491 )
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286620 |
|
Thu, 10 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Title | IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data | |
| First Time appeared |
Ibm
Ibm webmethods Integration Server |
|
| Weaknesses | CWE-91 | |
| CPEs | cpe:2.3:a:ibm:webmethods_integration_server:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:webmethods_integration_server:11.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm webmethods Integration Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-10T22:03:06.079Z
Reserved: 2026-02-10T21:27:08.332Z
Link: CVE-2026-2310
No data.
Status : Received
Published: 2026-09-10T22:16:55.833
Modified: 2026-09-10T22:16:55.833
Link: CVE-2026-2310
No data.
OpenCVE Enrichment
Updated: 2026-09-11T01:00:09Z