Ibm Infosphere Information Server vulnerabilities

196 known vulnerabilities affecting ibm/infosphere_information_server.

Total CVEs
196
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH41MEDIUM128LOW12

Vulnerabilities

Page 2 of 10
CVE-2025-36034MEDIUMCVSS 5.9v11.72025-06-26
CVE-2025-36034 [MEDIUM] CWE-319 CVE-2025-36034: IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.
cvelistv5nvd
CVE-2025-0966HIGHCVSS 7.6≥ 11.7, < 11.7.1v11.72025-06-25
CVE-2025-0966 [HIGH] CWE-89 CVE-2025-0966: IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send spe IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cvelistv5nvd
CVE-2025-3221HIGHCVSS 7.5≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62025-06-21
CVE-2025-3221 [HIGH] CWE-770 CVE-2025-3221: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
cvelistv5nvd
CVE-2025-3629MEDIUMCVSS 4.3≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62025-06-21
CVE-2025-3629 [MEDIUM] CWE-282 CVE-2025-3629: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to d IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.
cvelistv5nvd
CVE-2025-1499MEDIUMCVSS 6.5v11.72025-06-01
CVE-2025-1499 [MEDIUM] CWE-312 CVE-2025-1499: IBM InfoSphere Information Server 11.7 stores credential information for database authentication in IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
cvelistv5nvd
CVE-2025-1138MEDIUMCVSS 4.3v11.72025-05-15
CVE-2025-1138 [MEDIUM] CWE-548 CVE-2025-1138: IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.
cvelistv5nvd
CVE-2024-22351MEDIUMCVSS 6.3≥ 11.7, < 11.7.1v11.72025-04-23
CVE-2024-22351 [MEDIUM] CWE-613 CVE-2024-22351: IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
cvelistv5nvd
CVE-2025-25045MEDIUMCVSS 4.3≥ 11.7, < 11.7.1v11.72025-04-23
CVE-2025-25045 [MEDIUM] CWE-209 CVE-2025-25045: IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a det IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2025-25046LOWCVSS 3.7v11.72025-04-23
CVE-2025-25046 [LOW] CWE-319 CVE-2025-25046: IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
cvelistv5nvd
CVE-2024-7577HIGHCVSS 7.5≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-7577 [HIGH] CWE-532 CVE-2024-7577: IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files duri IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.
cvelistv5nvd
CVE-2024-43186MEDIUMCVSS 6.5≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-43186 [MEDIUM] CWE-256 CVE-2024-43186: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive informa IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
cvelistv5nvd
CVE-2024-51477MEDIUMCVSS 6.5≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-51477 [MEDIUM] CWE-203 CVE-2024-51477: IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username i IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
cvelistv5nvd
CVE-2024-55895MEDIUMCVSS 5.3≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-55895 [MEDIUM] CWE-209 CVE-2024-55895: IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2024-51459HIGHCVSS 7.8≥ 11.7, < 11.7.1.136v11.72025-03-19
CVE-2024-51459 [HIGH] CWE-280 CVE-2024-51459: IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due t IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
cvelistv5nvd
CVE-2024-40706MEDIUMCVSS 4.3v11.72025-01-24
CVE-2024-40706 [MEDIUM] CWE-497 CVE-2024-40706: IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version informa IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system.
cvelistv5nvd
CVE-2024-52363HIGHCVSS 7.5v11.72025-01-17
CVE-2024-52363 [HIGH] CWE-22 CVE-2024-52363: IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
cvelistv5nvd
CVE-2021-29827MEDIUMCVSS 5.2v11.72024-12-19
CVE-2021-29827 [MEDIUM] CWE-1021 CVE-2021-29827: IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action o IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
cvelistv5nvd
CVE-2024-52901MEDIUMCVSS 6.5v11.72024-12-12
CVE-2024-52901 [MEDIUM] CWE-1284 CVE-2024-52901: IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
cvelistv5nvd
CVE-2024-51460MEDIUMCVSS 4.3v11.72024-12-11
CVE-2024-51460 [MEDIUM] CWE-209 CVE-2024-51460: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive informa IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.
cvelistv5nvd
CVE-2023-23472MEDIUMCVSS 6.5v11.72024-12-11
CVE-2023-23472 [MEDIUM] CWE-497 CVE-2023-23472: IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authentic IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
cvelistv5nvd