cbcvebase.

Ibm Infosphere Information Server vulnerabilities

197 known vulnerabilities affecting ibm/infosphere_information_server.

Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12

Vulnerabilities

Page 10 of 10
CVE-2019-4257P4MEDIUMCVSS 4.3v11.5v11.72019-06-06
CVE-2019-4257 [MEDIUM] CWE-209 CVE-2019-4257: IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerabili IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.
nvd
CVE-2024-37533P4MEDIUMCVSS 4.6v11.72024-07-24
CVE-2024-37533 [MEDIUM] CWE-359 CVE-2024-37533: IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user wit IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.
nvd
CVE-2025-25045P4MEDIUMCVSS 4.3≥ 11.7, < 11.7.1v11.72025-04-23
CVE-2025-25045 [MEDIUM] CWE-209 CVE-2025-25045: IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a det IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.
nvd
CVE-2012-0702P4MEDIUMCVSS 4.0v8.1v8.5+3 more2013-01-31
CVE-2012-0702 [MEDIUM] CWE-287 CVE-2012-0702: Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8 Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2012-0203P4MEDIUMCVSS 4.3v8.1v8.5+2 more2013-01-31
CVE-2012-0203 [MEDIUM] CWE-79 CVE-2012-0203: Cross-site scripting (XSS) vulnerability in InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in I Cross-site scripting (XSS) vulnerability in InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0585P4LOWCVSS 3.5v8.1v8.5+2 more2013-08-16
CVE-2013-0585 [LOW] CWE-79 CVE-2013-0585: Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to the (1) web console and (2) repository management user interfaces.
nvd
CVE-2025-25046P4LOWCVSS 3.7v11.72025-04-23
CVE-2025-25046 [LOW] CWE-319 CVE-2025-25046: IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
nvd
CVE-2013-3034P4LOWCVSS 3.5≤ 8.5v8.1+2 more2013-08-16
CVE-2013-3034 [LOW] CWE-79 CVE-2013-3034: Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 t Cross-site scripting (XSS) vulnerability in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the web console.
nvd
CVE-2015-7490P4LOWCVSS 3.1v8.5v8.5.0.1+11 more2016-03-03
CVE-2015-7490 [LOW] CWE-284 CVE-2015-7490: IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 throug IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.
nvd
CVE-2025-14808P4LOWCVSS 3.1≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2025-14808 [LOW] CWE-598 CVE-2025-14808: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensit IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
nvd
CVE-2020-4886P4LOWCVSS 3.3v11.72020-11-13
CVE-2020-4886 [LOW] CWE-922 CVE-2020-4886: IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that co IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.
nvd
CVE-2023-35022P4LOWCVSS 3.3v11.72024-06-30
CVE-2023-35022 [LOW] CWE-285 CVE-2023-35022: IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.
nvd
CVE-2023-50955P4LOWCVSS 2.7v11.72024-02-21
CVE-2023-50955 [LOW] CWE-36 CVE-2023-50955: IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the ab IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.
nvd
CVE-2012-4832P4LOWCVSS 1.9v8.1v8.5+3 more2013-01-31
CVE-2012-4832 [LOW] CWE-200 CVE-2012-4832: Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8 Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2012-0700P4LOWCVSS 1.9v8.1v8.5+3 more2013-01-31
CVE-2012-0700 [LOW] CWE-255 CVE-2012-0700: The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 bef The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly store credentials, which allows local users to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2015-1901P4LOWCVSS 1.9v8.5v8.5.0.1+10 more2015-06-28
CVE-2015-1901 [LOW] CWE-200 CVE-2015-1901: The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local use The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.
nvd
CVE-2013-5440P4LOWCVSS 2.1v8.0v8.1+3 more2013-12-18
CVE-2013-5440 [LOW] CWE-200 CVE-2013-5440: IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation.
nvd
Ibm Infosphere Information Server vulnerabilities | cvebase