IBM Product Security Update Advisory (CVE-2025-36014)
Overview
We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-36014
IBM Integration Bus for z/OS Versions: 10.1.0.0 and later and 10.1.0.5 and earlier
Resolved Vulnerabilities
Privilege escalation vulnerability via code injection in IBM Integration Bus for z/OS (CVE-2025-36014)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-36014
PH65769 in IBM Integration Bus for z/OS Version: 10.1.0.5 [2]
References
[1] Security Bulletin: IBM Integration Bus for z/OS is vulnerable to a privilege escalation attack ( CVE-2025-36014)
https://www.ibm.com/support/pages/node/7239003
[2] Fix Central
https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/Integration+Bus&release=10.1.0.5&platform=All&function=aparId&apars=PH65769