Software AG webMethods Integration Server Incorrect Access Control Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability exists in the Software AG webMethods Integration Server version 10.15.0 prior to Core_Fix7, specifically on the /WmAdmin/,/invoke/vm.server/login login page. This vulnerability allows remote attackers to access the administration panel and obtain hostname and version information. Exploitation involves sending an arbitrary username and a blank password to the login URI.

Impact

Exploitation of this vulnerability leads to unauthorized access to the administrative dashboard, where sensitive information such as the server's hostname, version details, and administrative API endpoints can be viewed.

Reproduction

To reproduce this vulnerability, send a request to the /WmAdmin/#/login/ URI with a dummy username (such as an asterisk) and a blank password. This will grant access to the administrative dashboard. To maintain the session, drop the /admin/navigation/license request, as sending it will log out the user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.