VendorsIBMinfosphere_information_serverany version
Vulnerabilities

IBM Infosphere Information Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2020-4305
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176677.
Published 2020-07-09 · Modified
9.3EPSS 0.045
CVE-2025-12531
IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability
Published 2025-11-03 · Analyzed
9.1EPSS 0.007
CVE-2023-22877
IBM InfoSphere Information Server CSV injection
Published 2023-08-28 · Modified
8.8EPSS 0.007
CVE-2025-36245
IBM InfoSphere Information Server command execution
Published 2025-09-29 · Analyzed
8.8EPSS 0.004
CVE-2023-38268
IBM InfoSphere Information Server cross-site request forgery
Published 2023-12-01 · Modified
8.8EPSS 0.003
CVE-2023-23473
IBM InfoSphere Information Server cross-site request forgery
Published 2023-08-28 · Modified
8.8EPSS 0.003
CVE-2024-51459
IBM InfoSphere Server Information command execution
Published 2025-03-19 · Analyzed
8.4EPSS 0.001
CVE-2025-33003
IBM InfoSphere Information Server is vulnerable to privilege escalation
Published 2025-10-31 · Analyzed
7.8EPSS 0.001
CVE-2025-0966
IBM InfoSphere Information Server SQL injection
Published 2025-06-25 · Analyzed
7.6EPSS 0.003
CVE-2023-40699
IBM InfoSphere Information Server denial of service
Published 2023-12-01 · Modified
7.5EPSS 0.011
CVE-2023-24959
IBM InfoSphere Information Server information disclosure
Published 2023-08-28 · Modified
7.5EPSS 0.006
CVE-2025-3221
IBM InfoSphere Information Server denial of service
Published 2025-06-21 · Analyzed
7.5EPSS 0.004
CVE-2025-14974
IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference
Published 2026-03-25 · Analyzed
7.5EPSS 0.003
CVE-2026-1567
IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability
Published 2026-03-03 · Analyzed
7.5EPSS 0.003
CVE-2024-7577
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
7.5EPSS 0.003
CVE-2026-9836
IBM DataStage Flow Designer application is affected by an information disclosure vulnerability
Published 2026-06-30 · Analyzed
7.5EPSS 0.002
CVE-2025-36258
IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password
Published 2026-03-25 · Analyzed
7.1EPSS 0.002
CVE-2024-51477
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
6.5EPSS 0.003
CVE-2024-43186
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
6.5EPSS 0.003
CVE-2025-14810
IBM InfoSphere Information Server is vulnerable due to insufficient session expiration
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2025-14807
IBM InfoSphere Information Server is vulnerable to HTTP header injection
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2026-1014
IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2025-14790
IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2024-22351
IBM InfoSphere Information Server session fixation
Published 2025-04-23 · Analyzed
6.3EPSS 0.002
CVE-2023-42019
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.9EPSS 0.005
CVE-2016-0250
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
Published 2018-03-12 · Modified
5.5EPSS 0.015
CVE-2023-42009
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2023-42022
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2023-43015
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2023-46174
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2025-14912
IBM InfoSphere Information Server is vulnerable to server-side request forgery
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
CVE-2026-2483
IBM InfoSphere Information Server Cross-Site Scripting
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
CVE-2026-1015
IBM InfoSphere Information Server is vulnerable to server-side request forgery
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
CVE-2022-41733
IBM InfoSphere Information Server denial of service
Published 2023-01-20 · Modified
5.3EPSS 0.007
CVE-2023-43021
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.3EPSS 0.007
CVE-2024-55895
IBM InfoSphere Information Server information disclosure
Published 2025-03-29 · Analyzed
5.3EPSS 0.003
CVE-2026-1265
IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file
Published 2026-03-03 · Analyzed
5.3EPSS 0.002
CVE-2026-2485
IBM InfoSphere Information Server Cross-Site Scripting
Published 2026-03-25 · Analyzed
4.8EPSS 0.002
CVE-2025-12832
IBM InfoSphere Information Server Server-Side Request Forgery
Published 2025-12-08 · Analyzed
4.6EPSS 0.002
CVE-2025-25045
IBM InfoSphere Information Server information disclosure
Published 2025-04-23 · Analyzed
4.3EPSS 0.003
1 / 2Next →