VendorsIBMinfosphere_information_serverall versions
Vulnerabilities

IBM Infosphere Information Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2009-4240
Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.
Published 2009-12-09 · Modified
10.0EPSS 0.021
CVE-2020-27583
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2021-01-21 · Modified
9.8EPSS 0.037
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
Published 2022-11-16 · Modified
9.8EPSS 0.018
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2022-31768
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Published 2022-06-06 · Modified
9.8EPSS 0.014
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2022-47984
IBM InfoSphere Information Server SQL injection
Published 2023-05-19 · Modified
9.8EPSS 0.007
CVE-2024-40689
IBM InfoSphere Information Server SQL injection
Published 2024-07-26 · Modified
9.8EPSS 0.005
CVE-2020-4305
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176677.
Published 2020-07-09 · Modified
9.3EPSS 0.045
CVE-2012-0204
Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Published 2013-01-31 · Modified
9.3EPSS 0.013
CVE-2017-1383
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.
Published 2017-08-02 · Modified
9.1EPSS 0.027
CVE-2018-1727
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.
Published 2019-02-15 · Modified
9.1EPSS 0.025
CVE-2021-38948
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.
Published 2021-11-02 · Modified
9.1EPSS 0.020
CVE-2022-40747
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."
Published 2022-11-03 · Modified
9.1EPSS 0.010
CVE-2025-12531
IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability
Published 2025-11-03 · Analyzed
9.1EPSS 0.007
CVE-2021-29730
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 201164.
Published 2021-07-09 · Modified
8.8EPSS 0.010
CVE-2023-22877
IBM InfoSphere Information Server CSV injection
Published 2023-08-28 · Modified
8.8EPSS 0.007
CVE-2021-29888
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.
Published 2021-11-02 · Modified
8.8EPSS 0.005
CVE-2025-36245
IBM InfoSphere Information Server command execution
Published 2025-09-29 · Analyzed
8.8EPSS 0.004
CVE-2023-38268
IBM InfoSphere Information Server cross-site request forgery
Published 2023-12-01 · Modified
8.8EPSS 0.003
CVE-2023-23473
IBM InfoSphere Information Server cross-site request forgery
Published 2023-08-28 · Modified
8.8EPSS 0.003
CVE-2022-30608
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295.
Published 2022-11-03 · Modified
8.8EPSS 0.003
CVE-2024-31902
IBM InfoSphere Information Server cross-site request forgery
Published 2024-06-30 · Modified
8.8EPSS 0.003
CVE-2018-1701
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
Published 2019-02-15 · Modified
8.5EPSS 0.012
CVE-2017-1350
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.
Published 2018-06-05 · Modified
8.4EPSS 0.005
CVE-2024-51459
IBM InfoSphere Server Information command execution
Published 2025-03-19 · Analyzed
8.4EPSS 0.001
CVE-2019-4185
IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID: 158975.
Published 2019-06-06 · Modified
8.3EPSS 0.006
CVE-2017-1467
A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466.
Published 2017-08-02 · Modified
8.1EPSS 0.020
CVE-2016-6059
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Published 2017-02-01 · Modified
8.1EPSS 0.015
CVE-2013-0507
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
Published 2020-02-05 · Modified
8.1EPSS 0.012
CVE-2023-40363
IBM InfoSphere Information Server privilege escalation
Published 2023-11-18 · Modified
8.1EPSS 0.006
CVE-2022-35717
"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.
Published 2022-11-03 · Modified
7.8EPSS 0.006
CVE-2017-1469
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
Published 2017-08-14 · Modified
7.8EPSS 0.004
CVE-2017-1468
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.
Published 2017-08-02 · Modified
7.8EPSS 0.004
CVE-2025-33003
IBM InfoSphere Information Server is vulnerable to privilege escalation
Published 2025-10-31 · Analyzed
7.8EPSS 0.001
CVE-2025-0966
IBM InfoSphere Information Server SQL injection
Published 2025-06-25 · Analyzed
7.6EPSS 0.003
CVE-2021-29747
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.
Published 2021-05-17 · Modified
7.5EPSS 0.019
CVE-2020-4347
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permissions for files used by WebSphere Application Server Network Deployment. IBM X-Force ID: 178412.
Published 2020-04-16 · Modified
7.5EPSS 0.018
CVE-2023-24960
IBM InfoSphere Information Server information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.014
CVE-2021-29875
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.
Published 2021-11-02 · Modified
7.5EPSS 0.011
1 / 5Next →