CVE-2025-36014: IBM Integration Bus for z/OS code injection
Published Jul 7, 2025
·Updated
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
Affected Software
3 affected components
IBM Integration Bus for z/OS>=10.1.0.0<=10.1.0.5
All of the following
IBM Integration Bus>=10.1.0.0<=10.1.0.5
IBM Z\/os
Remediation
Information
IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM Integration Bus for z/OS.
IBM Integration Bus for z/OS 10.1.0.0 - 10.1.0.5 z/OS only PH65769
Interim Fix for APAR (PH65769) is available to apply to 10.1.0.5 from IBM Fix Central
Event History
Jul 7, 2025
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-36014?
CVE-2025-36014 is considered a high-severity vulnerability due to its potential for code injection by privileged users.
2
How do I fix CVE-2025-36014?
To fix CVE-2025-36014, upgrading to a patched version of IBM Integration Bus for z/OS, above 10.1.0.5, is recommended.
3
Who is affected by CVE-2025-36014?
CVE-2025-36014 affects users of IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.5.
4
What type of attack does CVE-2025-36014 facilitate?
CVE-2025-36014 facilitates code injection attacks by users with access to the IIB install directory.
5
What is the impact of exploiting CVE-2025-36014?
Exploiting CVE-2025-36014 could allow an attacker to execute arbitrary code with elevated privileges.