VendorsIBMinfosphere_information_serverall versions
Vulnerabilities

IBM Infosphere Information Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2024-43186
IBM InfoSphere Information Server information disclosure
Published 2025-03-28 · Analyzed
6.5EPSS 0.003
CVE-2025-14810
IBM InfoSphere Information Server is vulnerable due to insufficient session expiration
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2025-14807
IBM InfoSphere Information Server is vulnerable to HTTP header injection
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2026-1014
IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2025-1499
IBM InfoSphere Information Server information disclosure
Published 2025-06-01 · Analyzed
6.5EPSS 0.002
CVE-2025-14790
IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information
Published 2026-03-25 · Analyzed
6.5EPSS 0.002
CVE-2020-4741
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188197.
Published 2020-10-12 · Modified
6.4EPSS 0.006
CVE-2020-4702
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187187.
Published 2020-09-04 · Modified
6.4EPSS 0.006
CVE-2024-28797
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
6.4EPSS 0.003
CVE-2024-22351
IBM InfoSphere Information Server session fixation
Published 2025-04-23 · Analyzed
6.3EPSS 0.002
CVE-2018-1518
IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.
Published 2018-10-18 · Modified
6.2EPSS 0.002
CVE-2023-24964
IBM InfoSphere Information Server information disclosure
Published 2023-02-17 · Modified
6.2EPSS 0.001
CVE-2023-22878
IBM InfoSphere Information Server information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.001
CVE-2017-1321
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
Published 2017-07-12 · Modified
6.1EPSS 0.010
CVE-2020-4727
IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Published 2020-09-25 · Modified
6.1EPSS 0.009
CVE-2016-5984
IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
Published 2017-02-01 · Modified
6.1EPSS 0.009
CVE-2018-1432
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360.
Published 2018-06-05 · Modified
6.1EPSS 0.007
CVE-2021-29712
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
Published 2021-07-09 · Modified
6.1EPSS 0.007
CVE-2022-22427
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.
Published 2022-04-28 · Modified
6.1EPSS 0.006
CVE-2023-50303
IBM InfoSphere Information Server cross-site scripting
Published 2024-02-28 · Analyzed
6.1EPSS 0.004
CVE-2018-1454
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.
Published 2018-06-05 · Modified
5.9EPSS 0.015
CVE-2023-42019
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.9EPSS 0.005
CVE-2025-36034
IBM InfoSphere DataStage Flow Designer information disclosure
Published 2025-06-26 · Analyzed
5.9EPSS 0.002
CVE-2013-4067
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors.
Published 2013-10-02 · Modified
5.8EPSS 0.012
CVE-2012-0703
Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2013-01-31 · Modified
5.8EPSS 0.010
CVE-2015-5021
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.
Published 2015-11-04 · Modified
5.5EPSS 0.023
CVE-2016-0250
XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
Published 2018-03-12 · Modified
5.5EPSS 0.015
CVE-2015-0180
The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors.
Published 2015-05-25 · Modified
5.5EPSS 0.010
CVE-2022-22373
An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X-Force ID: 221323.
Published 2022-07-01 · Modified
5.5EPSS 0.005
CVE-2021-29738
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 201302.
Published 2021-11-02 · Modified
5.5EPSS 0.005
CVE-2023-28529
IBM InfoSphere Information Server 11.7
Published 2023-05-19 · Modified
5.5EPSS 0.004
CVE-2016-8999
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.
Published 2017-02-01 · Modified
5.4EPSS 0.007
CVE-2022-40748
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236586.
Published 2022-09-23 · Modified
5.4EPSS 0.007
CVE-2019-4237
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
Published 2019-07-01 · Modified
5.4EPSS 0.007
CVE-2019-4238
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464.
Published 2019-04-25 · Modified
5.4EPSS 0.007
CVE-2020-4298
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.
Published 2020-05-19 · Modified
5.4EPSS 0.006
CVE-2020-4162
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174342.
Published 2020-03-10 · Modified
5.4EPSS 0.006
CVE-2020-4997
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192914
Published 2021-04-05 · Modified
5.4EPSS 0.005
CVE-2021-29771
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2021-11-02 · Modified
5.4EPSS 0.005
CVE-2021-38952
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211408.
Published 2022-04-28 · Modified
5.4EPSS 0.005
← Prev3 / 5Next →