Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing the vulnerability now by applying the mentioned core fixes or later core fixes for the affected versions and following the respective readme document. IS_11.1_Core_Fix14 or later Fixes can be downloaded and installed via IBM webMethods Update Manager. Refer to How to Download webMethods Software ( https://www.ibm.com/support/pages/node/7232491 )
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286620 |
|
Thu, 10 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Title | IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data | |
| First Time appeared |
Ibm
Ibm webmethods Integration Server |
|
| Weaknesses | CWE-91 | |
| CPEs | cpe:2.3:a:ibm:webmethods_integration_server:11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:webmethods_integration_server:11.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm webmethods Integration Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-11T20:31:09.333Z
Reserved: 2026-02-10T21:27:08.332Z
Link: CVE-2026-2310
No data.
Status : Awaiting Analysis
Published: 2026-09-10T22:16:55.833
Modified: 2026-09-11T21:17:09.280
Link: CVE-2026-2310
No data.
OpenCVE Enrichment
Updated: 2026-09-11T07:30:09Z