Product:

Infosphere_information_server

(Ibm)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 148
Date Id Summary Products Score Patch Annotated
2024-08-15 CVE-2024-40705 IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279. Infosphere_information_server 6.5
2019-04-25 CVE-2019-4238 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159464. Infosphere_information_server, Infosphere_information_server_on_cloud 5.4
2019-06-06 CVE-2019-4185 IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID: 158975. Infosphere_information_server, Infosphere_information_server_on_cloud 8.3
2019-06-17 CVE-2018-1845 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905. Infosphere_governance_catalog, Infosphere_information_server, Infosphere_information_server_business_glossary, Infosphere_information_server_metadata_workbench, Infosphere_information_server_on_cloud 7.1
2019-07-01 CVE-2019-4237 A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419. Infosphere_information_governance_catalog, Infosphere_information_server, Infosphere_information_server_on_cloud 5.4
2022-09-29 CVE-2012-4818 IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system. Infosphere_information_server 6.5
2018-06-05 CVE-2018-1454 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089. Infosphere_information_server 5.9
2018-06-05 CVE-2018-1432 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360. Infosphere_information_server 6.1
2020-02-05 CVE-2013-0507 IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability Infosphere_information_server N/A
2017-07-12 CVE-2017-1321 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916. Infosphere_information_server, Infosphere_information_server_on_cloud N/A