VYPR

Infosphere Information Server

by IBM

CVEs (200)

  • CVE-2020-4632MedSep 4, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Metadata Asset Manager 11.7 is vulnerable to server-side request forgery. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to submit or control server requests. IBM X-Force ID: 185416.

  • CVE-2020-4286MedMay 19, 2020
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176268.

  • CVE-2016-5994MedFeb 1, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on the engine tier, and examine its contents.

  • CVE-2025-14810MedMar 25, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613:…

  • CVE-2024-22351MedApr 23, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2022-47984MedMay 19, 2023
    risk 0.41cvss 6.3epss 0.01

    IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163.

  • CVE-2018-1994MedApr 10, 2019
    risk 0.41cvss 6.3epss 0.02

    IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.

  • CVE-2023-50303MedFeb 28, 2024
    risk 0.40cvss 6.1epss 0.00

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2023-22878MedMay 19, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 244373.

  • CVE-2023-24964MedFeb 17, 2023
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.

  • CVE-2022-22427MedApr 28, 2022
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2021-29712MedJul 9, 2021
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2020-4727MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2018-1518MedOct 18, 2018
    risk 0.40cvss 6.2epss 0.00

    IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.

  • CVE-2018-1432MedJun 5, 2018
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise…

  • CVE-2017-1321MedJul 12, 2017
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2016-9000MedFeb 1, 2017
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this…

  • CVE-2016-5984MedFeb 1, 2017
    risk 0.40cvss 6.1epss 0.01

    IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this…

  • CVE-2024-40689MedJul 26, 2024
    risk 0.39cvss 6.0epss 0.01

    IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719.

  • CVE-2023-42019MedDec 1, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper input validation. IBM X-Force ID: 265161.

Page 4 of 10