CVEs (189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Infosphere Information Server Nov 21, 2024 Feb 15, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive i...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudNov 21, 2024 Feb 15, 2019 N/A· v4 8.5 HIGH· v3 6.0 MEDIUM· v2 IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudNov 21, 2024 Oct 18, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682. |
1Ibm 1Infosphere Information Server Nov 21, 2024 Jun 5, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit thi...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Jun 5, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a mal...Show more |
1Ibm 1Infosphere Information Server Nov 21, 2024 Jun 5, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526. |
1Ibm 1Infosphere Information Server Nov 21, 2024 Mar 12, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of servic...Show more |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 14, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 2, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive informa...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudMay 13, 2026 Jul 12, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten...Show more |
1Ibm 1Infosphere Information Server May 13, 2026 Feb 8, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information. |
1Ibm 3Infosphere Datastage Infosphere Information ServerInfosphere Information Server On CloudMay 13, 2026 Feb 1, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS. |
1Ibm 3Infosphere Datastage Infosphere Information ServerInfosphere Information Server On CloudMay 13, 2026 Feb 1, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly...Show more |
1Ibm 1Infosphere Information Server May 13, 2026 Feb 1, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents. |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudMay 13, 2026 Feb 1, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a w...Show more |
IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie. |
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors. |