Known vulnerabilities in webMethods BPM - page 2
Vendor:
IBM Corporation
Software:
webMethods BPM
Software CPE:
cpe:2.3:a:ibm_corporation:webmethods_bpm:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
52
Public exploits:
8
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (52)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU121014 - Resource exhaustion CVE-2025-8885 |
CWE-400 | Medium | 10.15 Fix 25, 11.1 Fix 7 | 07.01.2026 |
SB2024050731 SB2026010745 SB2026010827 and 10 more |
||
| #VU121006 - Out-of-bounds read CVE-2025-12183 |
CWE-125 | Medium | 11.1 Fix 9 | 07.01.2026 |
SB2026010701 SB2026010705 SB2026010706 and 14 more |
||
| #VU114443 - Session Fixation CVE-2025-55668 |
CWE-384 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 26.08.2025 |
SB2025082650 SB2025082651 SB2025090566 and 15 more |
||
| #VU112275 - Resource Management Errors CVE-2025-52520 |
CWE-399 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 42 more |
||
| #VU111161 - Resource exhaustion CVE-2025-48988 |
CWE-400 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 40 more |
||
| #VU111159 - Improper Protection of Alternate Path CVE-2025-49125 |
CWE-424 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 35 more |
||
| #VU109959 - Improper Handling of Case Sensitivity CVE-2025-46701 |
CWE-178 | Low | 10.15 Fix 14, 11.1 Fix 2 | 30.05.2025 |
SB2025053002 SB2025061335 SB2025062313 and 22 more |
||
| #VU107995 - Improper input validation CVE-2025-31651 |
CWE-20 | Medium | 10.15 Fix 14, 11.1 Fix 2 | 28.04.2025 |
SB2025042851 SB2025050943 SB2025050982 and 46 more |
||
| #VU105485 - Improper input validation CVE-2025-24813 |
CWE-20 | Critical | 10.15 Fix 14, 11.1 Fix 2 | 10.03.2025 |
SB2025031069 SB2025031976 SB2025032642 and 48 more |
||
| #VU100780 - Exposure of sensitive information to an unauthorized actor CVE-2024-31141 |
CWE-200 | Medium | 11.1 Fix 9 | 21.11.2024 |
SB2024112150 SB2024120226 SB2024120331 and 34 more |
||
| #VU98517 - Resource exhaustion CVE-2024-8184 |
CWE-400 | Medium | 11.1 Fix 6 | 14.10.2024 |
SB20241014108 SB2024101836 SB2024112849 and 38 more |
||
| #VU98516 - Server-Side Request Forgery (SSRF) CVE-2024-6763 |
CWE-918 | Medium | 11.1 Fix 6 | 14.10.2024 |
SB20241014107 SB2024112849 SB2024120517 and 49 more |
||
| #VU82454 - Allocation of Resources Without Limits or Throttling CVE-2023-43642 |
CWE-770 | Medium | 11.1 Fix 9 | 26.10.2023 |
SB2023102621 SB2023102628 SB2023103020 and 63 more |
||
| #VU77362 - Resource exhaustion CVE-2023-34455 |
CWE-400 | Medium | 11.1 Fix 9 | 15.06.2023 |
SB2023061517 SB2023071708 SB2023072511 and 48 more |
||
| #VU77361 - Integer overflow CVE-2023-34454 |
CWE-190 | Medium | 11.1 Fix 9 | 15.06.2023 |
SB2023061517 SB2023071708 SB2023072511 and 39 more |
||
| #VU77359 - Integer overflow CVE-2023-34453 |
CWE-190 | Medium | 11.1 Fix 9 | 15.06.2023 |
SB2023061517 SB2023071708 SB2023072511 and 40 more |
||
| #VU74271 - Resource exhaustion CVE-2012-2098 |
CWE-400 | Medium | 11.1 Fix 9 | 31.03.2023 |
SB2012062904 SB2023040315 SB2023040465 and 10 more |
||
| #VU72123 - Deserialization of Untrusted Data CVE-2023-25194 |
CWE-502 | Low | 11.1 Fix 9 | 11.02.2023 |
SB2023021101 SB2023030952 SB2023040419 and 40 more |
||
| #VU67489 - Resource exhaustion CVE-2022-34917 |
CWE-400 | Medium | 11.1 Fix 9 | 20.09.2022 |
SB2022092020 SB2022100556 SB2022110304 and 21 more |
||
| #VU59098 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44832 |
CWE-94 | Medium | 11.1 Fix 6 | 28.12.2021 |
SB2021122816 SB2021123002 SB2022010601 and 197 more |
Showing elements 21 - 40 out of 52