Ibm Infosphere Information Server vulnerabilities

196 known vulnerabilities affecting ibm/infosphere_information_server.

Total CVEs
196
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH41MEDIUM128LOW12

Vulnerabilities

Page 8 of 10
CVE-2019-4220MEDIUMCVSS 5.5v11.7.1.02019-06-06
CVE-2019-4220 [MEDIUM] CWE-798 CVE-2019-4220: IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be u IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.
cvelistv5nvd
CVE-2019-4238MEDIUMCVSS 5.4v11.3v11.5+1 more2019-04-25
CVE-2019-4238 [MEDIUM] CWE-79 CVE-2019-4238: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This v IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464.
cvelistv5nvd
CVE-2018-1994CRITICALCVSS 9.8v11.5v11.72019-04-10
CVE-2018-1994 [CRITICAL] CWE-89 CVE-2018-1994: IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker co IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.
cvelistv5nvd
CVE-2018-1906MEDIUMCVSS 6.5v11.3v11.5+1 more2019-04-02
CVE-2018-1906 [MEDIUM] CVE-2018-1906: IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663.
cvelistv5nvd
CVE-2018-1917MEDIUMCVSS 6.5v11.3v11.5+1 more2019-04-02
CVE-2018-1917 [MEDIUM] CWE-200 CVE-2018-1917: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access J IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
cvelistv5nvd
CVE-2018-1899MEDIUMCVSS 4.3v11.3v11.5+1 more2019-03-05
CVE-2018-1899 [MEDIUM] CVE-2018-1899: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.
cvelistv5nvd
CVE-2018-1727CRITICALCVSS 9.1v9.1v11.3+2 more2019-02-15
CVE-2018-1727 [CRITICAL] CWE-611 CVE-2018-1727: IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity I IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.
cvelistv5nvd
CVE-2018-1701HIGHCVSS 8.5v11.72019-02-15
CVE-2018-1701 [HIGH] CVE-2018-1701: IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
cvelistv5nvd
CVE-2018-1895MEDIUMCVSS 5.4v11.3v11.5+1 more2019-02-15
CVE-2018-1895 [MEDIUM] CWE-79 CVE-2018-1895: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This v IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152159.
cvelistv5nvd
CVE-2018-1518MEDIUMCVSS 5.5v11.72018-10-18
CVE-2018-1518 [MEDIUM] CWE-326 CVE-2018-1518: IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
cvelistv5nvd
CVE-2017-1350HIGHCVSS 7.8v9.1v11.3+2 more2018-06-05
CVE-2017-1350 [HIGH] CVE-2017-1350: IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their pri IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.
cvelistv5nvd
CVE-2018-1432MEDIUMCVSS 6.1v9.1v11.3+2 more2018-06-05
CVE-2018-1432 [MEDIUM] CWE-352 CVE-2018-1432: IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting w IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social enginee
cvelistv5nvd
CVE-2018-1454MEDIUMCVSS 5.9v11.3v11.5+1 more2018-06-05
CVE-2018-1454 [MEDIUM] CWE-319 CVE-2018-1454: IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensi IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.
cvelistv5nvd
CVE-2016-0250MEDIUMCVSS 5.4≥ 11.3, < 11.3.1.2v11.52018-03-12
CVE-2016-0250 [MEDIUM] CWE-611 CVE-2016-0250: XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
nvd
CVE-2017-1469HIGHCVSS 7.8v9.1v11.3+1 more2017-08-14
CVE-2017-1469 [HIGH] CWE-94 CVE-2017-1469: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated priv IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
cvelistv5nvd
CVE-2017-1383CRITICALCVSS 9.1v9.1v11.3+1 more2017-08-02
CVE-2017-1383 [CRITICAL] CWE-611 CVE-2017-1383: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injecti IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.
cvelistv5nvd
CVE-2017-1468HIGHCVSS 7.8v9.1v11.3+1 more2017-08-02
CVE-2017-1468 [HIGH] CVE-2017-1468: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated priv IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.
cvelistv5nvd
CVE-2017-1467HIGHCVSS 8.1v9.1v11.3+1 more2017-08-02
CVE-2017-1467 [HIGH] CVE-2017-1467: A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466.
cvelistv5nvd
CVE-2017-1495MEDIUMCVSS 4.9v9.1v11.3+1 more2017-08-02
CVE-2017-1495 [MEDIUM] CWE-119 CVE-2017-1495: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memor IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.
cvelistv5nvd
CVE-2017-1321MEDIUMCVSS 6.1v9.1v11.3+1 more2017-07-12
CVE-2017-1321 [MEDIUM] CWE-79 CVE-2017-1321: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vu IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
cvelistv5nvd