IBM Vulnerabilities and Affected Products
Vulnerabilities associated with InfoSphere Information Server.
Products
Clear product- Db2 for Linux, UNIX and Windows168 vulnerabilities
- i162 vulnerabilities
- WebSphere Application Server152 vulnerabilities
- InfoSphere Information Server146 vulnerabilities
- Sterling B2B Integrator132 vulnerabilities
- Rational Quality Manager126 vulnerabilities
- Rational Collaborative Lifecycle Management114 vulnerabilities
- Security Guardium106 vulnerabilities
- QRadar SIEM100 vulnerabilities
- Cognos Analytics98 vulnerabilities
- Rational DOORS Next Generation91 vulnerabilities
- MQ83 vulnerabilities
- Maximo Asset Management81 vulnerabilities
- API Connect78 vulnerabilities
- Rational Engineering Lifecycle Manager76 vulnerabilities
- Rational Team Concert72 vulnerabilities
- AIX69 vulnerabilities
- Langflow OSS68 vulnerabilities
- Sterling File Gateway64 vulnerabilities
- Security Key Lifecycle Manager57 vulnerabilities
- Security Verify Access57 vulnerabilities
- Cloud Pak for Security55 vulnerabilities
- Cognos Controller52 vulnerabilities
- Engineering Lifecycle Optimization52 vulnerabilities
- Spectrum Protect Plus49 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
IBM DataStage Flow Designer application is affected by an information disclosure vulnerabilityIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. CWE-200Jun 30, 2026 | CVSS3.5v3.1 | EPSS0.241% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-14807MEDIUM | IBM InfoSphere Information Server is vulnerable to HTTP header injectionIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. CWE-644Mar 25, 2026 | CVSS6.5v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1015MEDIUM | IBM InfoSphere Information Server is vulnerable to server-side request forgeryIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. CWE-918Mar 25, 2026 | CVSS5.4v3.1 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1014MEDIUM | IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive informationIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation. CWE-319Mar 25, 2026 | CVSS6.5v3.1 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2483MEDIUM | IBM InfoSphere Information Server Cross-Site ScriptingIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session CWE-79Mar 25, 2026 | CVSS5.4v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2484MEDIUM | IBM InfoSphere Information Server Information DisclosureIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused by overly verbose error messages CWE-209Mar 25, 2026 | CVSS4.3v3.1 | EPSS0.284% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36422MEDIUM | IBM InfoSphere Information Server is vulnerable to cross-site request forgeryIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. CWE-352Mar 25, 2026 | CVSS4.3v3.1 | EPSS0.139% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36258HIGH | IBM InfoSphere Information Server is vulnerable due to plaintext storage of a passwordIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user. CWE-256Mar 25, 2026 | CVSS7.1v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2485MEDIUM | IBM InfoSphere Information Server Cross-Site ScriptingIBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. CWE-79Mar 25, 2026 | CVSS4.8v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14974MEDIUM | IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object ReferenceIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR). CWE-639Mar 25, 2026 | CVSS5.7v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1262MEDIUM | IBM InfoSphere Information Server Information DisclosureIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. CWE-209Mar 25, 2026 | CVSS4.3v3.1 | EPSS0.242% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14912MEDIUM | IBM InfoSphere Information Server is vulnerable to server-side request forgeryIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. CWE-918Mar 25, 2026 | CVSS5.4v3.1 | EPSS0.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14810MEDIUM | IBM InfoSphere Information Server is vulnerable due to insufficient session expirationIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613: Insufficient Session Expiration CVSS Source: IBM CVSS Base score: 6.3 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) CWE-613Mar 25, 2026 | CVSS6.3v3.1 | EPSS0.242% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive informationIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques. CWE-598Mar 25, 2026 | CVSS3.1v3.1 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-14790MEDIUM | IBM InfoSphere Information Server is vulnerable to disclosure of sensitive informationIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected credentials. CWE-522Mar 25, 2026 | CVSS6.5v3.1 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1567HIGH | IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerabilityIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server. CWE-611Mar 3, 2026 | CVSS7.1v3.1 | EPSS0.311% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1265MEDIUM | IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log fileIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file. CWE-532Mar 3, 2026 | CVSS4.3v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12832MEDIUM | IBM InfoSphere Information Server Server-Side Request ForgeryIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. CWE-918Dec 8, 2025 | CVSS4.6v3.1 | EPSS0.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12531HIGH | IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerabilityIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. CWE-611Nov 3, 2025 | CVSS7.1v3.1 | EPSS0.706% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-33003HIGH | IBM InfoSphere Information Server is vulnerable to privilege escalationIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a container due to execution with unnecessary privileges. CWE-250Oct 31, 2025 | CVSS7.8v3.1 | EPSS0.128% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36245HIGH | IBM InfoSphere Information Server command executionIBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. CWE-78Sep 29, 2025 | CVSS8.8v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-36034MEDIUM | IBM InfoSphere DataStage Flow Designer information disclosureIBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques. CWE-319Jun 26, 2025 | CVSS5.3v3.1 | EPSS0.145% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-0966HIGH | IBM InfoSphere Information Server SQL injectionIBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. CWE-89Jun 25, 2025 | CVSS7.6v3.1 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3629MEDIUM | IBM InfoSphere Information Server file manipulationIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management. CWE-282Jun 21, 2025 | CVSS4.3v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3221HIGH | IBM InfoSphere Information Server denial of serviceIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. CWE-770Jun 21, 2025 | CVSS7.5v3.1 | EPSS0.376% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |