CVE-2025-14807
- EPSS 0.05%
- Veröffentlicht 25.03.2026 20:46:59
- Zuletzt bearbeitet 26.03.2026 18:23:37
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, inc...
CVE-2026-1015
- EPSS 0.03%
- Veröffentlicht 25.03.2026 20:41:40
- Zuletzt bearbeitet 26.03.2026 18:14:41
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or fac...
CVE-2026-1014
- EPSS 0.02%
- Veröffentlicht 25.03.2026 20:40:53
- Zuletzt bearbeitet 26.03.2026 18:16:38
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to exposure of sensitive information via JSON server response manipulation.
CVE-2026-2483
- EPSS 0.03%
- Veröffentlicht 25.03.2026 20:39:42
- Zuletzt bearbeitet 26.03.2026 18:14:17
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...
CVE-2026-2484
- EPSS 0.03%
- Veröffentlicht 25.03.2026 20:36:11
- Zuletzt bearbeitet 31.03.2026 19:01:10
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused by overly verbose error messages
CVE-2025-36422
- EPSS 0.02%
- Veröffentlicht 25.03.2026 20:26:58
- Zuletzt bearbeitet 26.03.2026 18:17:08
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow Designer is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that th...
CVE-2025-36258
- EPSS 0.01%
- Veröffentlicht 25.03.2026 20:25:21
- Zuletzt bearbeitet 26.03.2026 18:18:27
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.
CVE-2026-2485
- EPSS 0.03%
- Veröffentlicht 25.03.2026 20:22:51
- Zuletzt bearbeitet 26.03.2026 18:05:28
IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall...
CVE-2025-14974
- EPSS 0.09%
- Veröffentlicht 25.03.2026 20:20:27
- Zuletzt bearbeitet 26.03.2026 18:21:02
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).
CVE-2026-1262
- EPSS 0.03%
- Veröffentlicht 25.03.2026 20:19:24
- Zuletzt bearbeitet 26.03.2026 18:14:26
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.