VendorsIBMinfosphere_information_serverall versions
Vulnerabilities

IBM Infosphere Information Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2023-40699
IBM InfoSphere Information Server denial of service
Published 2023-12-01 · Modified
7.5EPSS 0.011
CVE-2022-35715
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.
Published 2022-08-10 · Modified
7.5EPSS 0.010
CVE-2021-29737
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.
Published 2021-11-02 · Modified
7.5EPSS 0.007
CVE-2024-52363
IBM InfoSphere Information Server directory traversal
Published 2025-01-17 · Analyzed
7.5EPSS 0.006
CVE-2023-30441
IBM Java information disclosure
Published 2023-04-29 · Modified
7.5EPSS 0.006
CVE-2023-24959
IBM InfoSphere Information Server information disclosure
Published 2023-08-28 · Modified
7.5EPSS 0.006
CVE-2026-9836
IBM DataStage Flow Designer application is affected by an information disclosure vulnerability
Published 2026-06-30 · Analyzed
7.5EPSS 0.004
CVE-2025-3221
IBM InfoSphere Information Server denial of service
Published 2025-06-21 · Analyzed
7.5EPSS 0.004
CVE-2025-14974
IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference
Published 2026-03-25 · Analyzed
7.5EPSS 0.003
CVE-2026-1567
IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability
Published 2026-03-03 · Analyzed
7.5EPSS 0.003
CVE-2024-7577
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
7.5EPSS 0.003
CVE-2012-5938
The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for unspecified files, which allows local users to bypass intended access restrictions via standard filesystem operations.
Published 2013-03-20 · Modified
7.2EPSS 0.004
CVE-2011-3123
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
Published 2011-08-10 · Modified
7.2EPSS 0.004
CVE-2011-3124
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.
Published 2011-08-10 · Modified
7.2EPSS 0.004
CVE-2024-28798
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
7.2EPSS 0.003
CVE-2018-1845
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
Published 2019-06-17 · Modified
7.1EPSS 0.020
CVE-2012-0705
InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.
Published 2013-01-31 · Modified
7.1EPSS 0.018
CVE-2025-36258
IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password
Published 2026-03-25 · Analyzed
7.1EPSS 0.002
CVE-2013-4057
Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
Published 2014-03-16 · Modified
6.8EPSS 0.007
CVE-2013-4056
Cross-site request forgery (CSRF) vulnerability in the Data Quality Console and Information Analyzer components in IBM InfoSphere Information Server 8.7 through FP2 and 9.1 through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.
Published 2013-10-13 · Modified
6.8EPSS 0.006
CVE-2018-1906
IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663.
Published 2019-04-02 · Modified
6.5EPSS 0.019
CVE-2018-1917
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
Published 2019-04-02 · Modified
6.5EPSS 0.014
CVE-2012-4818
IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system.
Published 2020-08-28 · Modified
6.5EPSS 0.014
CVE-2016-5994
IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents.
Published 2017-02-01 · Modified
6.5EPSS 0.012
CVE-2013-4058
Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.
Published 2014-03-16 · Modified
6.5EPSS 0.012
CVE-2012-0205
InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use of the troubleshooting feature, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (workbench outage) via unspecified vectors.
Published 2013-01-31 · Modified
6.5EPSS 0.011
CVE-2012-0701
The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.
Published 2013-01-31 · Modified
6.5EPSS 0.011
CVE-2022-22441
IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.
Published 2022-04-28 · Modified
6.5EPSS 0.009
CVE-2021-38887
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.
Published 2021-11-10 · Modified
6.5EPSS 0.008
CVE-2022-40235
"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725."
Published 2022-11-03 · Modified
6.5EPSS 0.007
CVE-2024-40705
IBM InfoSphere Information Server denial of service
Published 2024-08-15 · Analyzed
6.5EPSS 0.006
CVE-2022-36772
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
Published 2022-10-07 · Modified
6.5EPSS 0.006
CVE-2024-52901
IBM InfoSphere Information Server denial of service
Published 2024-12-12 · Analyzed
6.5EPSS 0.005
CVE-2023-35898
IBM InfoSphere Information Server information disclosure
Published 2023-07-19 · Modified
6.5EPSS 0.005
CVE-2022-22442
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."
Published 2022-11-03 · Modified
6.5EPSS 0.005
CVE-2024-22352
IBM InfoSphere Information Server information disclosure
Published 2024-03-05 · Modified
6.5EPSS 0.005
CVE-2020-4286
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176268.
Published 2020-05-19 · Modified
6.5EPSS 0.005
CVE-2022-41291
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
Published 2022-10-07 · Modified
6.5EPSS 0.004
CVE-2023-23472
IBM InfoSphere Information Server information disclosure
Published 2024-12-11 · Analyzed
6.5EPSS 0.003
CVE-2024-51477
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
6.5EPSS 0.003
← Prev2 / 5Next →