VYPR
Medium severity5.4NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2025-14290

CVE-2025-14290

Description

IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An SSRF in the IBM webMethods Integration Server Admin UI lets authenticated attackers send unauthorized requests, enabling network enumeration or further attacks.

Vulnerability

IBM webMethods Integration (on prem) – Integration Server versions 10.15 through IS_10.15_Core_Fix26 and 11.1 through IS_11.1_Core_Fix10 contain a server-side request forgery (SSRF) vulnerability [1]. The flaw resides in the Administration > Publishing > Add subscriber Admin UI page, which does not properly validate user-supplied URLs, allowing an attacker to make the server issue HTTP requests to arbitrary destinations [1].

Exploitation

An attacker must be authenticated to the Administration interface and navigate to the affected page [1]. By providing a crafted URL in the subscriber configuration, they can trigger the server to initiate outbound HTTP connections to internal or external systems under the identity of the Integration Server [1]. No special network position beyond access to the admin web console is required.

Impact

Successful exploitation allows the attacker to send unauthorized HTTP requests from the Integration Server. This can be used to probe internal network services (network enumeration) or as a stepping stone for further attacks [1]. The CVSS score of 5.4 (medium) indicates limited impact to confidentiality and integrity, but no direct impact on availability [1].

Mitigation

IBM released core fixes to address this vulnerability: IS_10.15_Core_Fix27 (or later) for the 10.15 stream, and IS_11.1_Core_Fix11 (or later) for the 11.1 stream [1]. These fixes can be applied via IBM webMethods Update Manager [1]. No workarounds are provided, so applying the appropriate core fix is the only remediation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.