CVE-2025-11548

CRITICAL

ibi WebFOCUS - Privilege Escalation

Title source: llm
STIX 2.1

Description

A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution

Scores

CVSS v4 9.3
EPSS 0.0048
EPSS Percentile 37.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
ibi/WebFOCUS 9.1 - 3
ibi/WebFOCUS 9.2 - 2
Published Oct 14, 2025
Tracked Since Feb 18, 2026