VYPR

Infosphere Information Server

by IBM

CVEs (200)

  • CVE-2016-6059HigFeb 1, 2017
    risk 0.53cvss 8.1epss 0.02

    IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory…

  • CVE-2025-33003HigOct 31, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a container due to execution with unnecessary privileges.

  • CVE-2022-35717HigNov 3, 2022
    risk 0.51cvss 7.8epss 0.01

    "IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-"Force ID: 231361.

  • CVE-2022-22454HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2017-1469HigAug 14, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.

  • CVE-2017-1468HigAug 2, 2017
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.

  • CVE-2025-0966HigJun 25, 2025
    risk 0.49cvss 7.6epss 0.00

    IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2025-3221HigJun 21, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

  • CVE-2023-40699HigDec 1, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.

  • CVE-2023-30441HigApr 29, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.

  • CVE-2023-24960HigFeb 17, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333

  • CVE-2022-35715HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231202.

  • CVE-2021-29875HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.

  • CVE-2021-29737HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.

  • CVE-2021-29747HigMay 17, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.

  • CVE-2020-4347HigApr 16, 2020
    risk 0.48cvss 7.3epss 0.02

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could be subject to attacks based on privilege escalation due to inappropriate file permissions for files used by WebSphere Application Server Network Deployment. IBM X-Force ID: 178412.

  • CVE-2018-1875HigMar 5, 2019
    risk 0.48cvss 7.4epss 0.01

    IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof…

  • CVE-2024-28798HigJun 30, 2024
    risk 0.47cvss 7.2epss 0.00

    IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. …

  • CVE-2025-36258HigMar 25, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.

  • CVE-2026-1567HigMar 3, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.

Page 2 of 10