VendorsIBMinfosphere_information_serverall versions
Vulnerabilities

IBM Infosphere Information Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2022-22322
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218370.
Published 2022-04-28 · Modified
5.4EPSS 0.005
CVE-2022-22443
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224440.
Published 2022-04-28 · Modified
5.4EPSS 0.005
CVE-2022-35642
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592."
Published 2022-11-03 · Modified
5.4EPSS 0.004
CVE-2022-47983
IBM InfoSphere Information Server cross-site scripting
Published 2023-02-01 · Modified
5.4EPSS 0.004
CVE-2022-30615
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227592.
Published 2022-11-03 · Modified
5.4EPSS 0.004
CVE-2023-42022
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2023-43015
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2023-42009
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2023-46174
IBM InfoSphere Information Server cross-site scripting
Published 2023-12-01 · Modified
5.4EPSS 0.004
CVE-2022-40753
IBM InfoSphere Information Server cross-site scripting
Published 2022-11-11 · Modified
5.4EPSS 0.004
CVE-2023-25928
IBM InfoSphere Information Server cross-site scripting
Published 2023-02-21 · Modified
5.4EPSS 0.004
CVE-2023-33843
IBM InfoSphere Information Server cross-site scripting
Published 2024-02-21 · Analyzed
5.4EPSS 0.004
CVE-2023-50953
IBM InfoSphere Information Server information disclosure
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-28795
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-31898
IBM InfoSphere Information Server data modification
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2023-50964
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-28794
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
5.4EPSS 0.003
CVE-2024-40690
IBM InfoSphere Server cross-site scripting
Published 2024-07-12 · Modified
5.4EPSS 0.002
CVE-2023-50952
IBM InfoSphere Information Server server-side request forgery
Published 2024-06-30 · Modified
5.4EPSS 0.002
CVE-2025-14912
IBM InfoSphere Information Server is vulnerable to server-side request forgery
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
CVE-2026-2483
IBM InfoSphere Information Server Cross-Site Scripting
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
CVE-2026-1015
IBM InfoSphere Information Server is vulnerable to server-side request forgery
Published 2026-03-25 · Analyzed
5.4EPSS 0.002
CVE-2021-29681
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
Published 2021-05-21 · Modified
5.3EPSS 0.009
CVE-2022-41733
IBM InfoSphere Information Server denial of service
Published 2023-01-20 · Modified
5.3EPSS 0.007
CVE-2023-43021
IBM InfoSphere Information Server information disclosure
Published 2023-12-01 · Modified
5.3EPSS 0.007
CVE-2023-33857
IBM InfoSphere Information Server information disclosure
Published 2023-07-16 · Modified
5.3EPSS 0.007
CVE-2024-35119
IBM InfoSphere Information Server information disclosure
Published 2024-06-30 · Modified
5.3EPSS 0.004
CVE-2024-40706
IBM InfoSphere Information Server information disclosure
Published 2025-01-24 · Analyzed
5.3EPSS 0.004
CVE-2023-50954
IBM InfoSphere Information Server information disclosure
Published 2024-06-30 · Modified
5.3EPSS 0.004
CVE-2024-55895
IBM InfoSphere Information Server information disclosure
Published 2025-03-29 · Analyzed
5.3EPSS 0.003
CVE-2026-1265
IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file
Published 2026-03-03 · Analyzed
5.3EPSS 0.002
CVE-2020-4740
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 188150.
Published 2020-10-12 · Modified
5.2EPSS 0.007
CVE-2021-29827
IBM InfoSphere Information Server clickjacking
Published 2024-12-18 · Analyzed
5.2EPSS 0.003
CVE-2013-3040
IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.
Published 2013-08-16 · Modified
5.0EPSS 0.014
CVE-2017-1495
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.
Published 2017-08-02 · Modified
4.9EPSS 0.013
CVE-2024-40704
IBM InfoSphere Information Server information disclosure
Published 2024-08-15 · Analyzed
4.9EPSS 0.006
CVE-2026-2485
IBM InfoSphere Information Server Cross-Site Scripting
Published 2026-03-25 · Analyzed
4.8EPSS 0.002
CVE-2015-7493
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.
Published 2017-02-08 · Modified
4.7EPSS 0.003
CVE-2023-23475
IBM Infosphere Information Server cross-site scripting
Published 2023-02-08 · Modified
4.6EPSS 0.003
CVE-2024-37533
IBM InfoSphere Information Server information disclosure
Published 2024-07-24 · Modified
4.6EPSS 0.002
← Prev4 / 5Next →