← Back

Infosphere Information Server

infosphere_information_server

Vendor: Ibm • 189 CVEs

CVEs (189)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Infosphere Information Server
Jun 17, 2026
Sep 29, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jun 26, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jun 25, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-en...Show more
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jun 21, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jun 21, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Jun 17, 2026
Jun 1, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Jun 17, 2026
May 15, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 23, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 23, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the s...Show more
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 23, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Mar 29, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks...Show more
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Mar 29, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Mar 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Mar 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Mar 19, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handling of permissions.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jan 24, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jan 17, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary f...Show more
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Dec 19, 2024
N/A· v4
5.2 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability t...Show more
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Dec 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Dec 11, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further att...Show more
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.Show less