CVE-2023-23472Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Infosphere Information Server

Severity
6.5MEDIUMNVD
CNA3.1
EPSS
0.1%
top 70.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11

Description

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
IBM InfoSphere Information Server information disclosure2024-12-11
GHSA
GHSA-8q4m-8m4v-c2rm: IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 112024-12-11