cbcvebase.

Ibm Infosphere Information Server vulnerabilities

197 known vulnerabilities affecting ibm/infosphere_information_server.

Total CVEs
197
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH42MEDIUM128LOW12

Vulnerabilities

Page 8 of 10
CVE-2024-28795P4MEDIUMCVSS 5.4v11.72024-06-30
CVE-2024-28795 [MEDIUM] CWE-79 CVE-2024-28795: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286832.
nvd
CVE-2023-50964P4MEDIUMCVSS 5.4v11.72024-06-30
CVE-2023-50964 [MEDIUM] CWE-79 CVE-2023-50964: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 276102.
nvd
CVE-2024-28794P4MEDIUMCVSS 5.4v11.72024-06-30
CVE-2024-28794 [MEDIUM] CWE-79 CVE-2024-28794: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 286831.
nvd
CVE-2023-50954P4MEDIUMCVSS 5.3v11.72024-06-30
CVE-2023-50954 [MEDIUM] CWE-598 CVE-2023-50954: IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could b IBM InfoSphere Information Server 11.7 returns sensitive information in URL information that could be used in further attacks against the system. IBM X-Force ID: 275776.
nvd
CVE-2024-55895P4MEDIUMCVSS 5.3≥ 11.7, < 11.7.1v11.72025-03-29
CVE-2024-55895 [MEDIUM] CWE-209 CVE-2024-55895: IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2017-1495P4MEDIUMCVSS 4.9v9.1v11.3+1 more2017-08-02
CVE-2017-1495 [MEDIUM] CWE-119 CVE-2017-1495: IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memor IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.
nvd
CVE-2012-0205P4MEDIUMCVSS 6.5v8.1v8.5+3 more2013-01-31
CVE-2012-0205 [MEDIUM] CWE-264 CVE-2012-0205: InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 be InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use of the troubleshooting feature, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (workbench outage) via unspecified vectors.
nvd
CVE-2025-12832P4MEDIUMCVSS 4.3≥ 11.7, ≤ 11.7.1.6≥ 11.7.0.0, ≤ 11.7.1.62025-12-08
CVE-2025-12832 [MEDIUM] CWE-918 CVE-2025-12832: IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request for IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
nvd
CVE-2016-8999P4MEDIUMCVSS 5.4v8.7v9.1+2 more2017-02-01
CVE-2016-8999 [MEDIUM] CWE-79 CVE-2016-8999: IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allo IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
nvd
CVE-2019-4220P4MEDIUMCVSS 5.5v11.7.1.02019-06-06
CVE-2019-4220 [MEDIUM] CWE-798 CVE-2019-4220: IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be u IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.
nvd
CVE-2022-30615P4MEDIUMCVSS 5.4v11.72022-11-03
CVE-2022-30615 [MEDIUM] CWE-79 CVE-2022-30615: "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability al "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592.
nvd
CVE-2023-24964P4MEDIUMCVSS 5.5v11.72023-02-17
CVE-2023-24964 [MEDIUM] CWE-312 CVE-2023-24964: IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.
nvd
CVE-2023-25928P4MEDIUMCVSS 5.4v11.72023-02-21
CVE-2023-25928 [MEDIUM] CWE-79 CVE-2023-25928: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability all IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247646.
nvd
CVE-2023-22878P4MEDIUMCVSS 5.5v11.72023-05-19
CVE-2023-22878 [MEDIUM] CWE-312 CVE-2023-22878: IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.
nvd
CVE-2022-40753P4MEDIUMCVSS 5.4v11.72022-11-15
CVE-2022-40753 [MEDIUM] CWE-79 CVE-2022-40753: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability al IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236688.
nvd
CVE-2024-40704P4MEDIUMCVSS 4.9v11.7v11.7.0.1+1 more2024-08-15
CVE-2024-40704 [MEDIUM] CWE-522 CVE-2024-40704: IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers. IBM X-Force ID: 298277.
nvd
CVE-2018-1518P4MEDIUMCVSS 5.5v11.72018-10-18
CVE-2018-1518 [MEDIUM] CWE-326 CVE-2018-1518: IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
nvd
CVE-2013-3040P4MEDIUMCVSS 5.0v8.5v8.5.0.1+6 more2013-08-16
CVE-2013-3040 [MEDIUM] CWE-200 CVE-2013-3040: IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure m IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.
nvd
CVE-2021-29827P4MEDIUMCVSS 5.2v11.72024-12-19
CVE-2021-29827 [MEDIUM] CWE-1021 CVE-2021-29827: IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action o IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
nvd
CVE-2026-2485P4MEDIUMCVSS 4.8≥ 11.7.0.0, ≤ 11.7.1.62026-03-25
CVE-2026-2485 [MEDIUM] CWE-79 CVE-2026-2485: IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scrip IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
Ibm Infosphere Information Server vulnerabilities | cvebase