VendorsIBMinfosphere_information_server11.7
Vulnerabilities

IBM Infosphere Information Server 11.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

96CVEs
CVE-2025-1499
IBM InfoSphere Information Server information disclosure
Published 2025-06-01 · Analyzed
6.5EPSS 0.002
CVE-2020-4741
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188197.
Published 2020-10-12 · Modified
6.4EPSS 0.006
CVE-2020-4702
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187187.
Published 2020-09-04 · Modified
6.4EPSS 0.006
CVE-2024-28797
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
6.4EPSS 0.003
CVE-2018-1518
IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
Published 2018-10-18 · Modified
6.2EPSS 0.002
CVE-2023-24964
IBM InfoSphere Information Server information disclosure
Published 2023-02-17 · Modified
6.2EPSS 0.001
CVE-2023-22878
IBM InfoSphere Information Server information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.001
CVE-2020-4727
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Published 2020-09-25 · Modified
6.1EPSS 0.009
CVE-2018-1432
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360.
Published 2018-06-05 · Modified
6.1EPSS 0.007
CVE-2021-29712
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
Published 2021-07-09 · Modified
6.1EPSS 0.007
CVE-2022-22427
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.
Published 2022-04-28 · Modified
6.1EPSS 0.006
CVE-2023-50303
IBM InfoSphere Information Server cross-site scripting
Published 2024-02-28 · Analyzed
6.1EPSS 0.004
CVE-2018-1454
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.
Published 2018-06-05 · Modified
5.9EPSS 0.015
CVE-2025-36034
IBM InfoSphere DataStage Flow Designer information disclosure
Published 2025-06-26 · Analyzed
5.9EPSS 0.002
CVE-2022-22373
An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X-Force ID: 221323.
Published 2022-07-01 · Modified
5.5EPSS 0.005
CVE-2021-29738
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201302.
Published 2021-11-02 · Modified
5.5EPSS 0.005
CVE-2023-28529
IBM InfoSphere Information Server 11.7
Published 2023-05-19 · Modified
5.5EPSS 0.004
CVE-2022-40748
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236586.
Published 2022-09-23 · Modified
5.4EPSS 0.007
CVE-2019-4237
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
Published 2019-07-01 · Modified
5.4EPSS 0.007
CVE-2019-4238
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464.
Published 2019-04-25 · Modified
5.4EPSS 0.007
CVE-2020-4162
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.
Published 2020-03-10 · Modified
5.4EPSS 0.006
CVE-2020-4997
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192914
Published 2021-04-05 · Modified
5.4EPSS 0.005
CVE-2021-29771
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2021-11-02 · Modified
5.4EPSS 0.005
CVE-2021-38952
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211408.
Published 2022-04-28 · Modified
5.4EPSS 0.005
CVE-2022-22322
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218370.
Published 2022-04-28 · Modified
5.4EPSS 0.005
CVE-2022-22443
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224440.
Published 2022-04-28 · Modified
5.4EPSS 0.005
CVE-2022-35642
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592."
Published 2022-11-03 · Modified
5.4EPSS 0.004
CVE-2022-47983
IBM InfoSphere Information Server cross-site scripting
Published 2023-02-01 · Modified
5.4EPSS 0.004
CVE-2022-30615
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592.
Published 2022-11-03 · Modified
5.4EPSS 0.004
CVE-2022-40753
IBM InfoSphere Information Server cross-site scripting
Published 2022-11-11 · Modified
5.4EPSS 0.004
CVE-2023-25928
IBM InfoSphere Information Server cross-site scripting
Published 2023-02-21 · Modified
5.4EPSS 0.004
CVE-2023-33843
IBM InfoSphere Information Server cross-site scripting
Published 2024-02-21 · Analyzed
5.4EPSS 0.004
CVE-2023-50953
IBM InfoSphere Information Server information disclosure
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-28795
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-31898
IBM InfoSphere Information Server data modification
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2023-50964
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-28794
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-40690
IBM InfoSphere Server cross-site scripting
Published 2024-07-12 · Modified
5.4EPSS 0.002
CVE-2023-50952
IBM InfoSphere Information Server server-side request forgery
Published 2024-06-30 · Modified
5.4EPSS 0.002
CVE-2021-29681
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
Published 2021-05-21 · Modified
5.3EPSS 0.009
← Prev2 / 3Next →