IBM
IBM Infosphere Information Server: vulnerabilidades y CVE
IBM Infosphere Information Server tiene 189 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE189
Últimos 12 meses20
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9836 | Alta (7.5) | 0.45% | — | 30 jun 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. |
| CVE-2026-2485 | Media (4.8) | 0.19% | — | 25 mar 2026 | IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the… |
| CVE-2026-2484 | Media (4.3) | 0.28% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused by overly verbose error messages |
| CVE-2026-2483 | Media (5.4) | 0.21% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… |
| CVE-2026-1262 | Media (4.3) | 0.24% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. |
| CVE-2026-1015 | Media (5.4) | 0.21% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially… |
| CVE-2026-1014 | Media (6.5) | 0.21% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation. |
| CVE-2025-36422 | Media (4.3) | 0.14% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… |
| CVE-2025-36258 | Media (5.5) | 0.15% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user. |
| CVE-2025-14974 | Alta (7.5) | 0.33% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR). |
| CVE-2025-14912 | Media (5.4) | 0.22% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially… |
| CVE-2025-14810 | Media (6.5) | 0.24% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information.… |
| CVE-2025-14808 | Baja (3.1) | 0.22% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in… |
| CVE-2025-14807 | Media (6.5) | 0.22% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks… |
| CVE-2025-14790 | Media (6.5) | 0.20% | — | 25 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected credentials. |
| CVE-2026-1567 | Alta (7.5) | 0.32% | — | 3 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server. |
| CVE-2026-1265 | Media (5.3) | 0.20% | — | 3 mar 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file. |
| CVE-2025-12832 | Media (4.3) | 0.16% | — | 8 dic 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially… |
| CVE-2025-12531 | Crítica (9.1) | 0.71% | — | 3 nov 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive… |
| CVE-2025-33003 | Alta (7.8) | 0.13% | — | 31 oct 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a container due to execution with unnecessary privileges. |
| CVE-2025-36245 | Alta (8.8) | 0.45% | — | 29 sept 2025 | IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. |
| CVE-2025-36034 | Media (5.9) | 0.17% | — | 26 jun 2025 | IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques. |
| CVE-2025-0966 | Alta (7.6) | 0.32% | — | 25 jun 2025 | IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the… |
| CVE-2025-3629 | Media (4.3) | 0.22% | — | 21 jun 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management. |
| CVE-2025-3221 | Alta (7.5) | 0.44% | — | 21 jun 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. |
| CVE-2025-1499 | Media (6.5) | 0.21% | — | 1 jun 2025 | IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user. |
| CVE-2025-1138 | Media (4.3) | 0.28% | — | 15 may 2025 | IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing. |
| CVE-2025-25046 | Baja (3.7) | 0.18% | — | 23 abr 2025 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques. |
| CVE-2025-25045 | Media (4.3) | 0.30% | — | 23 abr 2025 | IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the… |
| CVE-2024-22351 | Media (6.3) | 0.25% | — | 23 abr 2025 | IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. |
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142Rational Engineering Lifecycle Manager · 141