Known vulnerabilities in webMethods BPM - page 2
Vendor:
IBM Corporation
Software:
webMethods BPM
Software CPE:
cpe:2.3:a:ibm_corporation:webmethods_bpm:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
60
Public exploits:
8
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (60)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU121006 - Out-of-bounds read CVE-2025-12183 |
CWE-125 | Medium | 11.1 Fix 9 | 07.01.2026 |
SB2026010701 SB2026010705 SB2026010706 and 14 more |
||
| #VU114443 - Session Fixation CVE-2025-55668 |
CWE-384 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 26.08.2025 |
SB2025082650 SB2025082651 SB2025090566 and 15 more |
||
| #VU112275 - Resource Management Errors CVE-2025-52520 |
CWE-399 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 42 more |
||
| #VU111161 - Resource exhaustion CVE-2025-48988 |
CWE-400 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 40 more |
||
| #VU111159 - Improper Protection of Alternate Path CVE-2025-49125 |
CWE-424 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 35 more |
||
| #VU109959 - Improper Handling of Case Sensitivity CVE-2025-46701 |
CWE-178 | Low | 10.15 Fix 14, 11.1 Fix 2 | 30.05.2025 |
SB2025053002 SB2025061335 SB2025062313 and 22 more |
||
| #VU107995 - Improper input validation CVE-2025-31651 |
CWE-20 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 46 more |
||
| #VU105485 - Improper input validation CVE-2025-24813 |
CWE-20 | Critical | 10.15 Fix 14, 11.1 Fix 2 | 10.03.2025 |
SB2025031069 SB2025031976 SB2025032642 and 48 more |
||
| #VU98517 - Resource exhaustion CVE-2024-8184 |
CWE-400 | Medium | 11.1 Fix 6 | 14.10.2024 |
SB20241014108 SB2024101836 SB2024112849 and 38 more |
||
| #VU98516 - Server-Side Request Forgery (SSRF) CVE-2024-6763 |
CWE-918 | Medium | 11.1 Fix 6 | 14.10.2024 |
SB20241014107 SB2024112849 SB2024120517 and 49 more |
||
| #VU74271 - Resource exhaustion CVE-2012-2098 |
CWE-400 | Medium | 11.1 Fix 9 | 31.03.2023 |
SB2012062904 SB2023040315 SB2023040465 and 10 more |
||
| #VU60367 - Security Features CVE-2022-24329 |
CWE-254 | Medium | 11.1 Fix 1 | 08.02.2022 |
SB2022020805 SB2022042218 SB2022071957 and 13 more |
||
| #VU59098 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44832 |
CWE-94 | Medium | 11.1 Fix 6 | 28.12.2021 |
SB2021122816 SB2021123002 SB2022010601 and 197 more |
||
| #VU55164 - Improper input validation CVE-2020-29582 |
CWE-20 | Medium | 11.1 Fix 1 | 21.07.2021 |
SB2021072128 SB2022012750 SB2022042257 and 8 more |
||
| #VU54856 - Resource exhaustion CVE-2021-36374 |
CWE-400 | Medium | 11.1 Fix 9 | 14.07.2021 |
SB2021071409 SB2021072011 SB2021101927 and 43 more |
||
| #VU54855 - Resource exhaustion CVE-2021-36373 |
CWE-400 | Medium | 11.1 Fix 9 | 14.07.2021 |
SB2021071409 SB2021072011 SB2022080830 and 16 more |
||
| #VU53973 - Improper input validation CVE-2021-28169 |
CWE-20 | Medium | 10.15 Fix 15, 11.1 Fix 3 | 09.06.2021 |
SB2021060910 SB2021061815 SB2021081922 and 36 more |
||
| #VU52385 - Improper input validation CVE-2020-27223 |
CWE-20 | Medium | 10.15 Fix 15, 11.1 Fix 3 | 21.04.2021 |
SB2021042107 SB2021063002 SB2021063034 and 19 more |
||
| #VU27924 - Incorrect Default Permissions CVE-2020-1945 |
CWE-276 | Low | 11.1 Fix 9 | 15.05.2020 |
SB2020051501 SB2020052114 SB2020060205 and 48 more |
||
| #VU47428 - Permissions, Privileges, and Access Controls CVE-2020-11979 |
CWE-264 | Low | 11.1 Fix 9 | 14.05.2020 |
SB2020100804 SB2020100815 SB2020111614 and 51 more |
Showing elements 21 - 40 out of 60