Ibm Infosphere Information Server vulnerabilities
197 known vulnerabilities affecting ibm/infosphere_information_server.
Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12
Vulnerabilities
Page 5 of 10
CVE-2016-0250P4MEDIUMCVSS 5.4≥ 11.3, < 11.3.1.2v11.52018-03-12
CVE-2016-0250 [MEDIUM] CWE-611 CVE-2016-0250: XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
nvd
CVE-2025-36034P4MEDIUMCVSS 5.9v11.72025-06-26
CVE-2025-36034 [MEDIUM] CWE-319 CVE-2025-36034: IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.
nvd
CVE-2021-29738P4MEDIUMCVSS 5.4v11.72021-11-02
CVE-2021-29738 [MEDIUM] CWE-918 CVE-2021-29738: IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201302.
nvd
CVE-2023-50952P4MEDIUMCVSS 5.4v11.72024-06-30
CVE-2023-50952 [MEDIUM] CWE-918 CVE-2023-50952: IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may
IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 275774.
nvd
CVE-2022-40235P4MEDIUMCVSS 6.5v11.72022-11-03
CVE-2022-40235 [MEDIUM] CWE-20 CVE-2022-40235: "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing
"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725."
nvd
CVE-2020-4286P4MEDIUMCVSS 6.5v11.3v11.5+1 more2020-05-19
CVE-2020-4286 [MEDIUM] CWE-352 CVE-2020-4286: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery w
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176268.
nvd
CVE-2018-1454P4MEDIUMCVSS 5.9v11.3v11.5+1 more2018-06-05
CVE-2018-1454 [MEDIUM] CWE-319 CVE-2018-1454: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensi
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.
nvd
CVE-2012-0701P4MEDIUMCVSS 6.5v8.1v8.5+3 more2013-01-31
CVE-2012-0701 [MEDIUM] CWE-264 CVE-2012-0701: The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSph
The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2024-31898P4MEDIUMCVSS 5.4v11.72024-06-30
CVE-2024-31898 [MEDIUM] CWE-639 CVE-2024-31898: IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. IBM X-Force ID: 288182.
nvd
CVE-2026-1265P4MEDIUMCVSS 5.3≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62026-03-03
CVE-2026-1265 [MEDIUM] CWE-532 CVE-2026-1265: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive In
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.
nvd
CVE-2020-4727P4MEDIUMCVSS 6.1v11.72020-09-25
CVE-2020-4727 [MEDIUM] CWE-1021 CVE-2020-4727: IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action o
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
nvd
CVE-2022-22373P4MEDIUMCVSS 5.4v11.72022-07-01
CVE-2022-22373 [MEDIUM] CVE-2022-22373: An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and
An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X-Force ID: 221323.
nvd
CVE-2023-33857P4MEDIUMCVSS 5.3v11.72023-07-17
CVE-2023-33857 [MEDIUM] CWE-200 CVE-2023-33857: IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information us
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695.
nvd
CVE-2026-2483P4MEDIUMCVSS 5.4≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2026-2483 [MEDIUM] CWE-79 CVE-2026-2483: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. T
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session
nvd
CVE-2013-4067P4MEDIUMCVSS 5.8v8.0v8.1+6 more2013-10-02
CVE-2013-4067 [MEDIUM] CWE-264 CVE-2013-4067: IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors.
nvd
CVE-2012-5938P4HIGHCVSS 7.2v8.1v8.5+2 more2013-03-20
CVE-2012-5938 [HIGH] CWE-264 CVE-2012-5938: The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Lin
The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for unspecified files, which allows local users to bypass intended access restrictions via standard filesystem operations.
nvd
CVE-2011-3123P4HIGHCVSS 7.2v8.5v8.5.0.12011-08-10
CVE-2011-3123 [HIGH] CWE-264 CVE-2011-3123: IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataS
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
nvd
CVE-2011-3124P4HIGHCVSS 7.2v8.5v8.5.0.12011-08-10
CVE-2011-3124 [HIGH] CWE-264 CVE-2011-3124: IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataS
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.
nvd
CVE-2013-4057P4MEDIUMCVSS 6.8v8.5v8.5.0.1+8 more2014-03-16
CVE-2013-4057 [MEDIUM] CWE-352 CVE-2013-4057: Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server
Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
nvd
CVE-2013-4056P4MEDIUMCVSS 6.8v8.7v8.7.0.1+4 more2013-10-13
CVE-2013-4056 [MEDIUM] CWE-352 CVE-2013-4056: Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer
Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server 8.7 through FP2 and 9.1 through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
nvd