CVE-2025-3629Improper Ownership Management in IBM Infosphere Information Server

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 84.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 21
Latest updateJun 23

Description

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/infosphere_information_server11.7.0.011.7.1.6
NVDibm/infosphere_information_server11.711.7.1.6

🔴Vulnerability Details

2
GHSA
GHSA-mxhg-fjcx-gv8x: IBM InfoSphere Information Server 112025-06-23
CVEList
IBM InfoSphere Information Server file manipulation2025-06-21
CVE-2025-3629 — Improper Ownership Management in IBM | cvebase