CVE-2025-36034Cleartext Transmission of Sensitive Info in IBM Infosphere Information Server

Severity
5.9MEDIUMNVD
CNA5.3
EPSS
0.0%
top 93.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26

Description

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-v5pq-p875-xfr3: IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 112025-06-26
CVEList
IBM InfoSphere DataStage Flow Designer information disclosure2025-06-26