Ibm Infosphere Information Server vulnerabilities
197 known vulnerabilities affecting ibm/infosphere_information_server.
Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12
Vulnerabilities
Page 1 of 10
CVE-2020-27583P3CRITICALCVSS 9.8v8.52021-01-26
CVE-2020-27583 [CRITICAL] CWE-502 CVE-2020-27583: IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which cou
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
nvd
CVE-2025-36245P3HIGHCVSS 8.8≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62025-09-29
CVE-2025-36245 [HIGH] CWE-78 CVE-2025-36245: IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to exe
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
nvd
CVE-2023-32336P3CRITICALCVSS 9.8v11.72023-05-22
CVE-2023-32336 [CRITICAL] CWE-502 CVE-2023-32336: IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to i
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.
nvd
CVE-2024-40689P3CRITICALCVSS 9.8v11.72024-07-26
CVE-2024-40689 [CRITICAL] CWE-89 CVE-2024-40689: IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719.
nvd
CVE-2022-22425P3CRITICALCVSS 9.8v11.72022-11-03
CVE-2022-22425 [CRITICAL] CWE-1236 CVE-2022-22425: "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacke
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
nvd
CVE-2025-12531P3CRITICALCVSS 9.1≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62025-11-03
CVE-2025-12531 [CRITICAL] CWE-611 CVE-2025-12531: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
nvd
CVE-2020-4305P3HIGHCVSS 8.8≥ 11.7.0.0, ≤ 11.7.1.1v11.3.0+4 more2020-07-09
CVE-2020-4305 [HIGH] CWE-502 CVE-2020-4305: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbi
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176677.
nvd
CVE-2022-31768P3CRITICALCVSS 9.8v11.72022-06-06
CVE-2022-31768 [CRITICAL] CWE-89 CVE-2022-31768: IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
nvd
CVE-2022-47984P3CRITICALCVSS 9.8v11.72023-05-19
CVE-2022-47984 [CRITICAL] CWE-89 CVE-2022-47984: IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163.
nvd
CVE-2018-1994P3CRITICALCVSS 9.8v11.5v11.72019-04-10
CVE-2018-1994 [CRITICAL] CWE-89 CVE-2018-1994: IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker co
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.
nvd
CVE-2022-40752P3CRITICALCVSS 9.8v11.72022-11-16
CVE-2022-40752 [CRITICAL] CWE-77 CVE-2022-40752: IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neu
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.
nvd
CVE-2021-29730P3HIGHCVSS 8.8v11.72021-07-09
CVE-2021-29730 [HIGH] CWE-89 CVE-2021-29730: IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 201164.
nvd
CVE-2021-38948P3CRITICALCVSS 9.1v11.72021-11-02
CVE-2021-38948 [CRITICAL] CWE-91 CVE-2021-38948: IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attac
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.
nvd
CVE-2025-0966P3HIGHCVSS 7.6≥ 11.7, < 11.7.1v11.72025-06-25
CVE-2025-0966 [HIGH] CWE-89 CVE-2025-0966: IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send spe
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2018-1727P3CRITICALCVSS 9.1v9.1v11.3+2 more2019-02-15
CVE-2018-1727 [CRITICAL] CWE-611 CVE-2018-1727: IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity I
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.
nvd
CVE-2023-22877P3HIGHCVSS 8.8≥ 11.7.0.0, < 11.7.1.0≥ 11.7.0.0, < 11.7.1.4+1 more2023-08-28
CVE-2023-22877 [HIGH] CWE-1236 CVE-2023-22877: IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker
IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.
nvd
CVE-2017-1383P3CRITICALCVSS 9.1v9.1v11.3+1 more2017-08-02
CVE-2017-1383 [CRITICAL] CWE-611 CVE-2017-1383: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injecti
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.
nvd
CVE-2022-40747P3CRITICALCVSS 9.1v11.72022-11-03
CVE-2022-40747 [CRITICAL] CWE-611 CVE-2022-40747: "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) atta
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."
nvd
CVE-2024-52363P3HIGHCVSS 7.5v11.72025-01-17
CVE-2024-52363 [HIGH] CWE-22 CVE-2024-52363: IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
nvd
CVE-2026-1567P3HIGHCVSS 7.5≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62026-03-03
CVE-2026-1567 [HIGH] CWE-611 CVE-2026-1567: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerabili
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
nvd
1 / 10Next →