IBM Product Security Update Advisory (CVE-2025-36202)

IBM Product Security Update Advisory (CVE-2025-36202)

Overview

 

We have released a security update to fix vulnerabilities in IBM products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-36202

 

IBM webMethods Integration (on prem) Version: 10.15
IBM webMethods Integration (on prem) Version: 11.1

 

 

Resolved Vulnerabilities

 

Remote code execution vulnerability in pub.xslt.transformSerialXML in IBM webMethods Integration (CVE-2025-36202)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-36202

 

IBM webMethods Integration (on prem) version: IS_10.15_Core_Fix22 or later
IBM webMethods Integration (on prem) version: IS_11.1_Core_Fix6 or later

 

 

References

 

[1] Security Bulletin: IBM webMethods Integration Sever is affected by remote code execution via pub.xslt.transformSerialXML
https://www.ibm.com/support/pages/node/7245720