Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

InfoSphere Information Server — Vulnerabilities & Security Advisories 152

All 152 CVE vulnerabilities found in InfoSphere Information Server, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the InfoSphere Information Server product developed by IBM. It aggregates security vulnerabilities, misconfigurations, and architectural flaws that impact the integrity, confidentiality, or availability of this data integration and governance platform. The collection includes reported issues ranging from injection flaws and buffer overflows to improper access controls and information exposure vulnerabilities. The database covers findings identified between 2010 and 2024, reflecting the long lifecycle of enterprise data management software and its evolving threat landscape. This range captures early implementations as well as more recent updates, providing a comprehensive view of how security postures have changed over time for this specific toolset. Visitors to this resource can effectively track vendor advisories issued by IBM in response to disclosed weaknesses. You can also gain a deeper understanding of specific weakness classes by seeing how they manifest within the context of enterprise data integration. Furthermore, the page allows you to look up a product's vulnerability history to assess long-term risk trends. By analyzing these aggregated data points, security professionals can identify recurring patterns, prioritize remediation efforts, and improve their overall risk management strategies for InfoSphere Information Server deployments. This structured approach helps in making informed decisions about patching, configuration hardening, and architectural reviews without relying on isolated incident reports.

Vendor: IBM Corporation

CVE IDTitleCVSSSeverityPublished
CVE-2026-9836 IBM DataStage Flow Designer application is affected by an information disclosure vulnerability CWE-200 3.5 Low2026-06-30
CVE-2025-14807 IBM InfoSphere Information Server is vulnerable to HTTP header injection CWE-644 6.5 Medium2026-03-25
CVE-2026-1015 IBM InfoSphere Information Server is vulnerable to server-side request forgery CWE-918 5.4 Medium2026-03-25
CVE-2026-1014 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information CWE-319 6.5 Medium2026-03-25
CVE-2026-2483 IBM InfoSphere Information Server Cross-Site Scripting CWE-79 5.4 Medium2026-03-25
CVE-2026-2484 IBM InfoSphere Information Server Information Disclosure CWE-209 4.3 Medium2026-03-25
CVE-2025-36422 IBM InfoSphere Information Server is vulnerable to cross-site request forgery CWE-352 4.3 Medium2026-03-25
CVE-2025-36258 IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password CWE-256 7.1 High2026-03-25
CVE-2026-2485 IBM InfoSphere Information Server Cross-Site Scripting CWE-79 4.8 Medium2026-03-25
CVE-2025-14974 IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference CWE-639 5.7 Medium2026-03-25
CVE-2026-1262 IBM InfoSphere Information Server Information Disclosure CWE-209 4.3 Medium2026-03-25
CVE-2025-14912 IBM InfoSphere Information Server is vulnerable to server-side request forgery CWE-918 5.4 Medium2026-03-25
CVE-2025-14810 IBM InfoSphere Information Server is vulnerable due to insufficient session expiration CWE-613 6.3 Medium2026-03-25
CVE-2025-14808 IBM InfoSphere Information Server is vulnerable due to disclosure of sensitive information CWE-598 3.1 Low2026-03-25
CVE-2025-14790 IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information CWE-522 6.5 Medium2026-03-25
CVE-2026-1567 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability CWE-611 7.1 High2026-03-03
CVE-2026-1265 IBM InfoSphere Information Server is vulnerable due to sensitive information written to a log file CWE-532 4.3 Medium2026-03-03
CVE-2025-12832 IBM InfoSphere Information Server Server-Side Request Forgery CWE-918 4.6 Medium2025-12-08
CVE-2025-12531 IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability CWE-611 7.1 High2025-11-03
CVE-2025-33003 IBM InfoSphere Information Server is vulnerable to privilege escalation CWE-250 7.8 High2025-10-31
CVE-2025-36245 IBM InfoSphere Information Server command execution CWE-78 8.8 High2025-09-29
CVE-2025-36034 IBM InfoSphere DataStage Flow Designer information disclosure CWE-319 5.3 Medium2025-06-26
CVE-2025-0966 IBM InfoSphere Information Server SQL injection CWE-89 7.6 High2025-06-25
CVE-2025-3629 IBM InfoSphere Information Server file manipulation CWE-282 4.3 Medium2025-06-21
CVE-2025-3221 IBM InfoSphere Information Server denial of service CWE-770 7.5 High2025-06-21
CVE-2025-1499 IBM InfoSphere Information Server information disclosure CWE-312 6.5 Medium2025-06-01
CVE-2025-1138 IBM Information Server information disclosure CWE-548 4.3 Medium2025-05-15
CVE-2025-25046 IBM InfoSphere Information Server information disclosure CWE-319 3.7 Low2025-04-23
CVE-2025-25045 IBM InfoSphere Information Server information disclosure CWE-209 4.3 Medium2025-04-23
CVE-2024-22351 IBM InfoSphere Information Server session fixation CWE-613 6.3 Medium2025-04-23

All 152 known CVE vulnerabilities affecting InfoSphere Information Server with full Chinese analysis, references, and POCs where available.