Ibm Infosphere Information Server vulnerabilities
197 known vulnerabilities affecting ibm/infosphere_information_server.
Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12
Vulnerabilities
Page 4 of 10
CVE-2025-3221P3HIGHCVSS 7.5≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62025-06-21
CVE-2025-3221 [HIGH] CWE-770 CVE-2025-3221: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2013-4058P3MEDIUMCVSS 6.5v8.5v8.5.0.1+8 more2014-03-16
CVE-2013-4058 [MEDIUM] CWE-89 CVE-2013-4058: Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7
Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.
nvd
CVE-2022-22441P3MEDIUMCVSS 6.5v11.72022-04-28
CVE-2022-22441 [MEDIUM] CVE-2022-22441: IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of high
IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.
nvd
CVE-2023-40363P3MEDIUMCVSS 6.5v11.72023-11-18
CVE-2023-40363 [MEDIUM] CWE-276 CVE-2023-40363: IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation file
IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect file permission settings. IBM X-Force ID: 263332.
nvd
CVE-2025-14807P4MEDIUMCVSS 6.5≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2025-14807 [MEDIUM] CWE-644 CVE-2025-14807: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection,
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
nvd
CVE-2018-1917P4MEDIUMCVSS 6.5v11.3v11.5+1 more2019-04-02
CVE-2018-1917 [MEDIUM] CWE-200 CVE-2018-1917: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access J
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
nvd
CVE-2024-40705P4MEDIUMCVSS 6.5v11.7v11.7.0.1+1 more2024-08-15
CVE-2024-40705 [MEDIUM] CWE-405 CVE-2024-40705: IBM InfoSphere Information Server could allow an authenticated user to consume file space resources
IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.
nvd
CVE-2023-35898P4MEDIUMCVSS 6.5v11.72023-07-19
CVE-2023-35898 [MEDIUM] CWE-200 CVE-2023-35898: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive informa
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352.
nvd
CVE-2022-22442P4MEDIUMCVSS 6.5v11.72022-11-03
CVE-2022-22442 [MEDIUM] CWE-284 CVE-2022-22442: "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information rest
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."
nvd
CVE-2024-22351P4MEDIUMCVSS 6.3≥ 11.7, < 11.7.1v11.72025-04-23
CVE-2024-22351 [MEDIUM] CWE-613 CVE-2024-22351: IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
nvd
CVE-2021-38887P4MEDIUMCVSS 6.5v11.72021-11-10
CVE-2021-38887 [MEDIUM] CVE-2021-38887: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive informa
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.
nvd
CVE-2022-36772P4MEDIUMCVSS 6.5v11.72022-10-07
CVE-2022-36772 [MEDIUM] CVE-2022-36772: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive informa
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
nvd
CVE-2024-52901P4MEDIUMCVSS 6.5v11.72024-12-12
CVE-2024-52901 [MEDIUM] CWE-1284 CVE-2024-52901: IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
nvd
CVE-2022-41291P4MEDIUMCVSS 6.5v11.72022-10-07
CVE-2022-41291 [MEDIUM] CWE-613 CVE-2022-41291: IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
nvd
CVE-2023-23472P4MEDIUMCVSS 6.5v11.72024-12-11
CVE-2023-23472 [MEDIUM] CWE-497 CVE-2023-23472: IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authentic
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
nvd
CVE-2024-51477P4MEDIUMCVSS 6.5≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-51477 [MEDIUM] CWE-203 CVE-2024-51477: IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username i
IBM InfoSphere Information Server 11.7
could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
nvd
CVE-2024-43186P4MEDIUMCVSS 6.5≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-43186 [MEDIUM] CWE-256 CVE-2024-43186: IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive informa
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
nvd
CVE-2025-14912P4MEDIUMCVSS 5.4≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2025-14912 [MEDIUM] CWE-918 CVE-2025-14912: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request for
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2026-1015P4MEDIUMCVSS 5.4≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2026-1015 [MEDIUM] CWE-918 CVE-2026-1015: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request for
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2016-5994P4MEDIUMCVSS 6.5v11.52017-02-01
CVE-2016-5994 [MEDIUM] CWE-200 CVE-2016-5994: IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to
IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents.
nvd