📦 Infosphere Information Server

by Ibm

🔍 What is Infosphere Information Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-31768

CRITICAL CVSS 9.8 Jun 6, 2022

This SQL injection vulnerability in IBM InfoSphere Information Server 11.7 allows remote attackers to execute arbitrary SQL commands against the back-end database. Attackers could potentially view, mo...

CVE-2021-38948

CRITICAL CVSS 9.1 Nov 2, 2021

IBM InfoSphere Information Server 11.7 has an XML External Entity Injection (XXE) vulnerability that allows attackers to read sensitive files from the server or cause denial of service through resourc...

CVE-2020-27583

CRITICAL CVSS 9.8 Jan 26, 2021

CVE-2020-27583 is a critical Java deserialization vulnerability in IBM InfoSphere Information Server 8.5.0.0 that allows unauthenticated remote attackers to execute arbitrary code on affected systems....

CVE-2026-1567

HIGH CVSS 7.1 Mar 3, 2026

This XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server allows attackers to read sensitive files from the server by exploiting improper XML parsing. Organizations running aff...

CVE-2025-12531

HIGH CVSS 7.1 Nov 3, 2025

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain an XML external entity injection (XXE) vulnerability that allows remote attackers to read sensitive files from the server o...

CVE-2025-33003

HIGH CVSS 7.8 Oct 31, 2025

This vulnerability in IBM InfoSphere Information Server allows non-root users within a container environment to escalate their privileges to root-level capabilities. It affects versions 11.7.0.0 throu...

CVE-2025-3221

HIGH CVSS 7.5 Jun 21, 2025

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain a resource exhaustion vulnerability due to insufficient validation of incoming requests. A remote attacker could send speci...

CVE-2024-28798

HIGH CVSS 7.2 Jun 30, 2024

IBM InfoSphere Information Server 11.7 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. This could enab...

CVE-2023-40699

HIGH CVSS 7.5 Dec 1, 2023

IBM InfoSphere Information Server 11.7 has an improper input validation vulnerability that allows remote attackers to cause denial of service. This affects organizations running vulnerable versions of...

CVE-2023-32336

HIGH CVSS 8.8 May 22, 2023

IBM InfoSphere Information Server 11.7 has a remote code execution vulnerability due to insecure deserialization in an RMI service. Attackers can exploit this to execute arbitrary code on affected sys...

CVE-2023-30441

HIGH CVSS 7.5 Apr 29, 2023

This vulnerability in IBM Runtime Environment Java Technology Edition's IBMJCEPlus and JSSE components could expose sensitive information due to cryptographic weaknesses. It affects IBM Java 8.0.7.0 t...

CVE-2021-29875

HIGH CVSS 7.5 Nov 2, 2021

IBM InfoSphere Information Server 11.7 has an insecure third-party domain access vulnerability that could allow attackers to obtain sensitive information. This affects organizations running vulnerable...

CVE-2021-29730

HIGH CVSS 8.8 Jul 9, 2021

CVE-2021-29730 is a SQL injection vulnerability in IBM InfoSphere Information Server 11.7 that allows remote attackers to execute arbitrary SQL commands. This could enable attackers to view, modify, o...

CVE-2026-1265

MEDIUM CVSS 4.3 Mar 3, 2026

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 write sensitive information to log files, potentially exposing credentials or other confidential data. This affects organizations u...

CVE-2025-12832

MEDIUM CVSS 4.6 Dec 8, 2025

This CVE describes a server-side request forgery (SSRF) vulnerability in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6. An authenticated attacker could exploit this to send unau...

CVE-2025-36034

MEDIUM CVSS 5.3 Jun 26, 2025

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 transmits sensitive user information in unencrypted API requests, allowing attackers to intercept this data via man-in-...

CVE-2025-1138

MEDIUM CVSS 4.3 May 15, 2025

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where authenticated users can access directory listings that reveal sensitive system information. This could pro...

CVE-2024-22351

MEDIUM CVSS 6.3 Apr 23, 2025

IBM InfoSphere Information Server 11.7 fails to properly invalidate user sessions after logout, allowing authenticated users to reuse old session tokens to impersonate other users. This affects organi...

CVE-2024-7577

MEDIUM CVSS 4.4 Mar 29, 2025

IBM InfoSphere Information Server 11.7 may expose sensitive user credentials in log files during new installations. This vulnerability allows attackers with access to installation logs to obtain authe...

CVE-2024-43186

MEDIUM CVSS 5.3 Mar 29, 2025

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where authenticated users can access sensitive local data under certain conditions. This affects organizations u...

CVE-2024-40706

MEDIUM CVSS 5.3 Jan 24, 2025

IBM InfoSphere Information Server 11.7 exposes sensitive version information to remote users, which could be used for reconnaissance in targeted attacks. This affects systems running the vulnerable ve...

CVE-2024-52363

MEDIUM CVSS 6.5 Jan 17, 2025

IBM InfoSphere Information Server 11.7 contains a directory traversal vulnerability that allows remote attackers to read arbitrary files on the system by sending specially crafted URL requests contain...

CVE-2024-52901

MEDIUM CVSS 6.5 Dec 12, 2024

IBM InfoSphere Information Server 11.7 contains an improper input validation vulnerability in its GUI component. Authenticated users can cause the GUI to stop loading or become unresponsive, disruptin...

CVE-2024-40704

MEDIUM CVSS 4.9 Aug 15, 2024

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where privileged users can access sensitive authentication data from request headers. This affects organizations...

CVE-2024-40689

MEDIUM CVSS 6.0 Jul 26, 2024

IBM InfoSphere Information Server 11.7 contains a SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands. This could enable attackers to read, modify, or delete dat...

CVE-2024-28794

MEDIUM CVSS 5.4 Jun 30, 2024

IBM InfoSphere Information Server 11.7 contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious JavaScript into the web interface. This could enable atta...

CVE-2024-31898

MEDIUM CVSS 5.4 Jun 30, 2024

This vulnerability in IBM InfoSphere Information Server 11.7 allows authenticated users to bypass authorization controls and access or modify sensitive data they shouldn't have permission to view. It ...

CVE-2023-50953

MEDIUM CVSS 5.4 Jun 30, 2024

IBM InfoSphere Information Server 11.7 discloses sensitive technical error information to remote attackers. This information leakage could reveal system details useful for crafting further attacks. Or...

CVE-2024-35119

MEDIUM CVSS 5.3 Jun 30, 2024

IBM InfoSphere Information Server 11.7 discloses sensitive technical information in error messages, potentially revealing system details that could aid attackers in crafting further exploits. This aff...

CVE-2023-50954

MEDIUM CVSS 4.3 Jun 30, 2024

IBM InfoSphere Information Server 11.7 exposes sensitive information in URLs, potentially revealing system details that could aid attackers in reconnaissance or further exploitation. This affects orga...

CVE-2024-28795

MEDIUM CVSS 5.4 Jun 30, 2024

IBM InfoSphere Information Server 11.7 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the web interface. This could lead to session hijac...