Ibm Infosphere Information Server vulnerabilities
197 known vulnerabilities affecting ibm/infosphere_information_server.
Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12
Vulnerabilities
Page 6 of 10
CVE-2017-1321P4MEDIUMCVSS 6.1v9.1v11.3+1 more2017-07-12
CVE-2017-1321 [MEDIUM] CWE-79 CVE-2017-1321: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vu
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
nvd
CVE-2016-5984P4MEDIUMCVSS 6.1v8.7v9.1+2 more2017-02-01
CVE-2016-5984 [MEDIUM] CWE-79 CVE-2016-5984: IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTM
IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
nvd
CVE-2015-5021P4MEDIUMCVSS 5.5v11.3v11.52015-11-04
CVE-2015-5021 [MEDIUM] CWE-264 CVE-2015-5021: IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypas
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.
nvd
CVE-2018-1432P4MEDIUMCVSS 6.1v9.1v11.3+2 more2018-06-05
CVE-2018-1432 [MEDIUM] CWE-352 CVE-2018-1432: IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting w
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social enginee
nvd
CVE-2021-29712P4MEDIUMCVSS 6.1v11.72021-07-09
CVE-2021-29712 [MEDIUM] CWE-79 CVE-2021-29712: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
nvd
CVE-2022-22427P4MEDIUMCVSS 6.1v11.72022-04-28
CVE-2022-22427 [MEDIUM] CWE-79 CVE-2022-22427: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.
nvd
CVE-2023-50303P4MEDIUMCVSS 6.1v11.72024-02-28
CVE-2023-50303 [MEDIUM] CWE-79 CVE-2023-50303: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273333.
nvd
CVE-2024-28798P4MEDIUMCVSS 6.1v11.72024-06-30
CVE-2024-28798 [MEDIUM] CWE-79 CVE-2024-28798: IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerabil
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287172.
nvd
CVE-2023-42019P4MEDIUMCVSS 5.9≥ 11.7.0.0, < 11.7.1.0≥ 11.7.0.0, < 11.7.1.4+1 more2023-12-01
CVE-2023-42019 [MEDIUM] CWE-311 CVE-2023-42019: IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.
nvd
CVE-2019-4238P4MEDIUMCVSS 5.4v11.3v11.5+1 more2019-04-25
CVE-2019-4238 [MEDIUM] CWE-79 CVE-2019-4238: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This v
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464.
nvd
CVE-2022-41733P4MEDIUMCVSS 5.3fixed in 11.7.1.4v11.72023-01-20
CVE-2022-41733 [MEDIUM] CWE-20 CVE-2022-41733: IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the component
IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable until the process is restarted. IBM X-Force ID: 237583.
nvd
CVE-2024-28797P4MEDIUMCVSS 5.4v11.72024-06-30
CVE-2024-28797 [MEDIUM] CWE-79 CVE-2024-28797: IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerabil
IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 287136.
nvd
CVE-2024-40690P4MEDIUMCVSS 5.4v11.72024-07-12
CVE-2024-40690 [MEDIUM] CWE-79 CVE-2024-40690: IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authe
IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 297720.
nvd
CVE-2024-35119P4MEDIUMCVSS 5.3v11.72024-06-30
CVE-2024-35119 [MEDIUM] CWE-209 CVE-2024-35119: IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 290342.
nvd
CVE-2015-0180P4MEDIUMCVSS 5.5v8.1v8.5+4 more2015-05-25
CVE-2015-0180 [MEDIUM] CWE-284 CVE-2015-0180: The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote aut
The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors.
nvd
CVE-2024-22352P4MEDIUMCVSS 5.5v11.72024-03-21
CVE-2024-22352 [MEDIUM] CWE-532 CVE-2024-22352: IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that co
IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.
nvd
CVE-2019-4237P4MEDIUMCVSS 5.4v11.3v11.5+1 more2019-07-01
CVE-2019-4237 [MEDIUM] CWE-79 CVE-2019-4237: A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
nvd
CVE-2018-1895P4MEDIUMCVSS 5.4v11.3v11.5+1 more2019-02-15
CVE-2018-1895 [MEDIUM] CWE-79 CVE-2018-1895: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This v
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159.
nvd
CVE-2021-29681P4MEDIUMCVSS 5.3v11.72021-05-21
CVE-2021-29681 [MEDIUM] CVE-2021-29681: IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by in
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
nvd
CVE-2022-40748P4MEDIUMCVSS 5.4v11.72022-09-23
CVE-2022-40748 [MEDIUM] CWE-79 CVE-2022-40748: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236586.
nvd