VYPR

Infosphere Information Server

by IBM

CVEs (200)

  • CVE-2025-12531HigNov 3, 2025
    risk 0.46cvss 7.1epss 0.01

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2023-22877HigAug 28, 2023
    risk 0.46cvss 7.0epss 0.01

    IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.

  • CVE-2018-1845HigJun 17, 2019
    risk 0.46cvss 7.1epss 0.02

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.

  • CVE-2018-1727HigFeb 15, 2019
    risk 0.46cvss 7.1epss 0.02

    IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID:…

  • CVE-2026-1014MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.

  • CVE-2025-14807MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site…

  • CVE-2025-14790MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected credentials.

  • CVE-2025-1499MedJun 1, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

  • CVE-2024-52363MedJan 17, 2025
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

  • CVE-2024-52901MedDec 12, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

  • CVE-2024-40705MedAug 15, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.

  • CVE-2024-28797MedJun 30, 2024
    risk 0.42cvss 6.4epss 0.00

    IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. …

  • CVE-2024-22352MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.

  • CVE-2022-40235MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.01

    "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725."

  • CVE-2022-22442MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.01

    "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with elevated privileges due to improper access controls. IBM X-Force ID: 224427."

  • CVE-2022-41291MedOct 7, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699.

  • CVE-2022-36772MedOct 7, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.

  • CVE-2012-4818MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content…

  • CVE-2022-22441MedApr 28, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users and groups due to a privilege escalation vulnerability. IBM X-Force ID: 224426.

  • CVE-2021-38887MedNov 10, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information from application response requests that could be used in further attacks against the system. IBM X-Force ID: 209401.

Page 3 of 10