VendorsIBMinfosphere_information_server11.7
Vulnerabilities

IBM Infosphere Information Server 11.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

96CVEs
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
Published 2022-11-16 · Modified
9.8EPSS 0.018
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2022-31768
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Published 2022-06-06 · Modified
9.8EPSS 0.014
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2022-47984
IBM InfoSphere Information Server SQL injection
Published 2023-05-19 · Modified
9.8EPSS 0.007
CVE-2024-40689
IBM InfoSphere Information Server SQL injection
Published 2024-07-26 · Modified
9.8EPSS 0.005
CVE-2018-1727
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.
Published 2019-02-15 · Modified
9.1EPSS 0.025
CVE-2021-38948
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.
Published 2021-11-02 · Modified
9.1EPSS 0.020
CVE-2022-40747
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."
Published 2022-11-03 · Modified
9.1EPSS 0.010
CVE-2021-29730
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 201164.
Published 2021-07-09 · Modified
8.8EPSS 0.010
CVE-2021-29888
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.
Published 2021-11-02 · Modified
8.8EPSS 0.005
CVE-2022-30608
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295.
Published 2022-11-03 · Modified
8.8EPSS 0.003
CVE-2024-31902
IBM InfoSphere Information Server cross-site request forgery
Published 2024-06-30 · Modified
8.8EPSS 0.003
CVE-2018-1701
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
Published 2019-02-15 · Modified
8.5EPSS 0.012
CVE-2017-1350
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.
Published 2018-06-05 · Modified
8.4EPSS 0.005
CVE-2023-40363
IBM InfoSphere Information Server privilege escalation
Published 2023-11-18 · Modified
8.1EPSS 0.006
CVE-2022-35717
"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.
Published 2022-11-03 · Modified
7.8EPSS 0.006
CVE-2021-29747
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.
Published 2021-05-17 · Modified
7.5EPSS 0.019
CVE-2020-4347
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permissions for files used by WebSphere Application Server Network Deployment. IBM X-Force ID: 178412.
Published 2020-04-16 · Modified
7.5EPSS 0.018
CVE-2023-24960
IBM InfoSphere Information Server information disclosure
Published 2023-02-17 · Modified
7.5EPSS 0.014
CVE-2021-29875
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.
Published 2021-11-02 · Modified
7.5EPSS 0.011
CVE-2022-35715
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.
Published 2022-08-10 · Modified
7.5EPSS 0.010
CVE-2021-29737
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.
Published 2021-11-02 · Modified
7.5EPSS 0.007
CVE-2024-52363
IBM InfoSphere Information Server directory traversal
Published 2025-01-17 · Analyzed
7.5EPSS 0.006
CVE-2023-30441
IBM Java information disclosure
Published 2023-04-29 · Modified
7.5EPSS 0.006
CVE-2024-28798
IBM InfoSphere Information Server cross-site scripting
Published 2024-06-30 · Modified
7.2EPSS 0.003
CVE-2018-1845
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
Published 2019-06-17 · Modified
7.1EPSS 0.020
CVE-2018-1906
IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a specially crafted HTTP request. IBM X-Force ID: 152663.
Published 2019-04-02 · Modified
6.5EPSS 0.019
CVE-2018-1917
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
Published 2019-04-02 · Modified
6.5EPSS 0.014
CVE-2022-22441
IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.
Published 2022-04-28 · Modified
6.5EPSS 0.009
CVE-2021-38887
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.
Published 2021-11-10 · Modified
6.5EPSS 0.008
CVE-2022-40235
"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725."
Published 2022-11-03 · Modified
6.5EPSS 0.007
CVE-2024-40705
IBM InfoSphere Information Server denial of service
Published 2024-08-15 · Analyzed
6.5EPSS 0.006
CVE-2022-36772
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
Published 2022-10-07 · Modified
6.5EPSS 0.006
CVE-2024-52901
IBM InfoSphere Information Server denial of service
Published 2024-12-12 · Analyzed
6.5EPSS 0.005
CVE-2023-35898
IBM InfoSphere Information Server information disclosure
Published 2023-07-19 · Modified
6.5EPSS 0.005
CVE-2022-22442
"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."
Published 2022-11-03 · Modified
6.5EPSS 0.005
CVE-2024-22352
IBM InfoSphere Information Server information disclosure
Published 2024-03-05 · Modified
6.5EPSS 0.005
CVE-2022-41291
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.
Published 2022-10-07 · Modified
6.5EPSS 0.004
CVE-2023-23472
IBM InfoSphere Information Server information disclosure
Published 2024-12-11 · Analyzed
6.5EPSS 0.003
1 / 3Next →