CVE-2026-2310
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | webMethods Integration Server | 11.1 | affected |
Weaknesses
- CWE-91: CWE-91 XML Injection (aka Blind XPath Injection)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.