Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

InfoSphere Information Server — Vulnerabilities & Security Advisories 152

All 152 CVE vulnerabilities found in InfoSphere Information Server, with AI-generated Chinese analysis, references, and POCs.

This page documents common vulnerabilities and security weaknesses affecting IBM InfoSphere Information Server, categorized by specific weakness types and industry-standard tags. It aggregates known security flaws, configuration errors, and potential exploitation vectors that have been identified within this enterprise data integration and management platform over a significant historical period. The collection includes issues ranging from improper access control and input validation errors to information disclosure vulnerabilities that may expose sensitive business data or system configurations to unauthorized parties. Here, users can systematically track IBM’s security advisories and patches related to InfoSphere Information Server to assess their organization's exposure. The resource allows security professionals to understand the broader context of specific weakness classes as they manifest in this particular software environment, facilitating more effective risk assessments and remediation planning. By providing a centralized view of the product’s vulnerability history, this page supports informed decision-making for IT security teams responsible for maintaining the integrity and confidentiality of data integration infrastructure. The information is intended to aid in compliance auditing, penetration testing preparations, and long-term security posture improvement without promoting specific vendors or services. All entries are derived from publicly available security reports and vendor notifications, ensuring accuracy and relevance for enterprise security operations.

Vendor: IBM Corporation

CVE IDTitleCVSSSeverityPublished
CVE-2026-9836 IBM DataStage Flow Designer application is affected by an information disclosure vulnerability CWE-200 3.5 Low2026-06-30
CVE-2025-14807 IBM InfoSphere Information Server is vulnerable to HTTP header injection CWE-644 6.5 Medium2026-03-25
CVE-2026-1015 IBM InfoSphere Information Server is vulnerable to server-side request forgery CWE-918 5.4 Medium2026-03-25
CVE-2026-1014 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information CWE-319 6.5 Medium2026-03-25
CVE-2026-2483 IBM InfoSphere Information Server Cross-Site Scripting CWE-79 5.4 Medium2026-03-25
CVE-2026-2484 IBM InfoSphere Information Server Information Disclosure CWE-209 4.3 Medium2026-03-25
CVE-2025-36422 IBM InfoSphere Information Server is vulnerable to cross-site request forgery CWE-352 4.3 Medium2026-03-25
CVE-2025-36258 IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password CWE-256 7.1 High2026-03-25
CVE-2026-2485 IBM InfoSphere Information Server Cross-Site Scripting CWE-79 4.8 Medium2026-03-25
CVE-2025-14974 IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference CWE-639 5.7 Medium2026-03-25
CVE-2026-1262 IBM InfoSphere Information Server Information Disclosure CWE-209 4.3 Medium2026-03-25
CVE-2025-14912 IBM InfoSphere Information Server is vulnerable to server-side request forgery CWE-918 5.4 Medium2026-03-25
CVE-2025-14810 IBM InfoSphere Information Server is vulnerable due to insufficient session expiration CWE-613 6.3 Medium2026-03-25
CVE-2025-14808 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information CWE-598 3.1 Low2026-03-25
CVE-2025-14790 IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information CWE-522 6.5 Medium2026-03-25
CVE-2026-1567 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability CWE-611 7.1 High2026-03-03
CVE-2026-1265 IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file CWE-532 4.3 Medium2026-03-03
CVE-2025-12832 IBM InfoSphere Information Server Server-Side Request Forgery CWE-918 4.6 Medium2025-12-08
CVE-2025-12531 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability CWE-611 7.1 High2025-11-03
CVE-2025-33003 IBM InfoSphere Information Server is vulnerable to privilege escalation CWE-250 7.8 High2025-10-31
CVE-2025-36245 IBM InfoSphere Information Server command execution CWE-78 8.8 High2025-09-29
CVE-2025-36034 IBM InfoSphere DataStage Flow Designer information disclosure CWE-319 5.3 Medium2025-06-26
CVE-2025-0966 IBM InfoSphere Information Server SQL injection CWE-89 7.6 High2025-06-25
CVE-2025-3629 IBM InfoSphere Information Server file manipulation CWE-282 4.3 Medium2025-06-21
CVE-2025-3221 IBM InfoSphere Information Server denial of service CWE-770 7.5 High2025-06-21
CVE-2025-1499 IBM InfoSphere Information Server information disclosure CWE-312 6.5 Medium2025-06-01
CVE-2025-1138 IBM Information Server information disclosure CWE-548 4.3 Medium2025-05-15
CVE-2025-25046 IBM InfoSphere Information Server information disclosure CWE-319 3.7 Low2025-04-23
CVE-2025-25045 IBM InfoSphere Information Server information disclosure CWE-209 4.3 Medium2025-04-23
CVE-2024-22351 IBM InfoSphere Information Server session fixation CWE-613 6.3 Medium2025-04-23

All 152 known CVE vulnerabilities affecting InfoSphere Information Server with full Chinese analysis, references, and POCs where available.