Ibm Infosphere Information Server vulnerabilities
197 known vulnerabilities affecting ibm/infosphere_information_server.
Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12
Vulnerabilities
Page 3 of 10
CVE-2017-1469P3HIGHCVSS 7.8v9.1v11.3+1 more2017-08-14
CVE-2017-1469 [HIGH] CWE-94 CVE-2017-1469: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated priv
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
nvd
CVE-2017-1468P3HIGHCVSS 7.8v9.1v11.3+1 more2017-08-02
CVE-2017-1468 [HIGH] CVE-2017-1468: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated priv
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.
nvd
CVE-2021-29875P3HIGHCVSS 7.5v11.72021-11-02
CVE-2021-29875 [HIGH] CVE-2021-29875: IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due t
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.
nvd
CVE-2022-35715P3HIGHCVSS 7.5v11.72022-08-10
CVE-2022-35715 [HIGH] CWE-209 CVE-2022-35715: IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.
nvd
CVE-2024-51459P3HIGHCVSS 7.8≥ 11.7, < 11.7.1.136v11.72025-03-19
CVE-2024-51459 [HIGH] CWE-280 CVE-2024-51459: IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due t
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
nvd
CVE-2021-29737P3HIGHCVSS 7.5v11.72021-11-02
CVE-2021-29737 [HIGH] CWE-295 CVE-2021-29737: IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has imp
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.
nvd
CVE-2023-30441P3HIGHCVSS 7.5v11.72023-04-29
CVE-2023-30441 [HIGH] CWE-327 CVE-2023-30441: IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 compon
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
nvd
CVE-2009-4240P3CRITICALCVSS 10.0v8.12009-12-09
CVE-2009-4240 [CRITICAL] CWE-119 CVE-2009-4240: Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSp
Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.
nvd
CVE-2017-1350P3HIGHCVSS 7.8v9.1v11.3+2 more2018-06-05
CVE-2017-1350 [HIGH] CVE-2017-1350: IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their pri
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.
nvd
CVE-2012-0204P3CRITICALCVSS 9.3v8.1v8.5+4 more2013-01-31
CVE-2012-0204 [CRITICAL] CVE-2012-0204: Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSpher
Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2018-1906P3MEDIUMCVSS 6.5v11.3v11.5+1 more2019-04-02
CVE-2018-1906 [MEDIUM] CVE-2018-1906: IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download
IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663.
nvd
CVE-2025-14810P3MEDIUMCVSS 6.5≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2025-14810 [MEDIUM] CWE-613 CVE-2025-14810: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after priv
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613: Insufficient Session Expiration CVSS Source: IBM CVSS Base score: 6.3 CVSS Vector:
nvd
CVE-2026-1014P3MEDIUMCVSS 6.5≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2026-1014 [MEDIUM] CWE-319 CVE-2026-1014: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive i
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.
nvd
CVE-2013-0507P3HIGHCVSS 8.1v8.1v8.5+2 more2020-02-05
CVE-2013-0507 [HIGH] CWE-384 CVE-2013-0507: IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
nvd
CVE-2012-0705P3HIGHCVSS 7.1v8.1v8.5+4 more2013-01-31
CVE-2012-0705 [HIGH] CWE-20 CVE-2012-0705: InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM
InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.
nvd
CVE-2012-4818P3MEDIUMCVSS 6.5v8.1v8.5+1 more2022-09-29
CVE-2012-4818 [MEDIUM] CVE-2012-4818: IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to o
IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system.
nvd
CVE-2020-4632P3MEDIUMCVSS 6.5v11.72020-09-04
CVE-2020-4632 [MEDIUM] CWE-918 CVE-2020-4632: IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending
IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416.
nvd
CVE-2025-14790P3MEDIUMCVSS 6.5≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2025-14790 [MEDIUM] CWE-522 CVE-2025-14790: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensit
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected credentials.
nvd
CVE-2025-1499P3MEDIUMCVSS 6.5v11.72025-06-01
CVE-2025-1499 [MEDIUM] CWE-312 CVE-2025-1499: IBM InfoSphere Information Server 11.7 stores credential information for database authentication in
IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
nvd
CVE-2023-40699P3HIGHCVSS 7.5≥ 11.7.0.0, < 11.7.1.0≥ 11.7.0.0, < 11.7.1.4+1 more2023-12-01
CVE-2023-40699 [HIGH] CWE-20 CVE-2023-40699: IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.
nvd