« Volver al listado

CVE-2026-2606

Estado: AnalizadaMedia (6.5)—

IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access on the underlying server file system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-2606",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-2606",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-04T21:10:59.885017Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:ibm:webmethods_api_gateway_on_prem:10.11:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:webmethods_api_gateway_on_prem:10.11_fix3210.15:*:*:*:*:*:*:*"
          ],
          "vendor": "IBM",
          "product": "webMethods API Gateway (on-prem)",
          "versions": [
            {
              "status": "affected",
              "version": "10.11",
              "versionType": "semver",
              "lessThanOrEqual": "10.11_Fix32"
            },
            {
              "status": "affected",
              "version": "10.15",
              "versionType": "semver",
              "lessThanOrEqual": "10.15_Fix27"
            },
            {
              "status": "affected",
              "version": "11.1",
              "versionType": "semver",
              "lessThanOrEqual": "11.1_Fix7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-03-03T20:16:49.783",
  "references": [
    {
      "url": "https://www.ibm.com/support/pages/node/7261122",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access on the underlying server file system."
    },
    {
      "lang": "es",
      "value": "IBM webMethods API Gateway (en las instalaciones) 10.11 hasta 10.11_Fix3210.15 a 10.15_Fix2711.1 a 11.1_Fix7 IBM webMethods API Management (en las instalaciones) no valida correctamente la entrada proporcionada por el usuario pasada al parámetro url en el endpoint /createapi. Un atacante puede modificar este parámetro para usar un esquema URI file:// en lugar del esquema HTTPS:// esperado, lo que permite el acceso de lectura de archivos arbitrario no autorizado en el sistema de archivos del servidor subyacente."
    }
  ],
  "lastModified": "2026-06-17T10:31:23.343",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:webmethods_api_gateway:10.11:-:*:*:on-prem:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F534C50-6ADC-4BBC-83E5-973C72964118"
            },
            {
              "criteria": "cpe:2.3:a:ibm:webmethods_api_gateway:10.11:fix32:*:*:on-prem:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A86D588-0072-4EBE-9FA8-008A36A321D0"
            },
            {
              "criteria": "cpe:2.3:a:ibm:webmethods_api_gateway:10.15:-:*:*:on-prem:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40E92E62-E820-47B9-BF03-5AF3E32B48D8"
            },
            {
              "criteria": "cpe:2.3:a:ibm:webmethods_api_gateway:10.15:fix27:*:*:on-prem:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71FCF82E-9B8D-4636-8130-076316E4D35D"
            },
            {
              "criteria": "cpe:2.3:a:ibm:webmethods_api_gateway:11.1:-:*:*:on-prem:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "978540F2-00C6-4F15-ADB8-32AFF3503460"
            },
            {
              "criteria": "cpe:2.3:a:ibm:webmethods_api_gateway:11.1:fix7:*:*:on-prem:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02A837D5-879F-487E-A28F-55DB0C097F00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}