Vulnerabilities > IBM > Infosphere Information Server

DATE CVE VULNERABILITY TITLE RISK
2024-08-15 CVE-2024-40704 Insufficiently Protected Credentials vulnerability in IBM Infosphere Information Server 11.7/11.7.0.1/11.7.0.2
IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication request headers.
network
low complexity
ibm CWE-522
4.9
2024-08-15 CVE-2024-40705 Unspecified vulnerability in IBM Infosphere Information Server 11.7/11.7.0.1/11.7.0.2
IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads.
network
low complexity
ibm
6.5
2024-08-06 CVE-2024-39751 Information Exposure Through an Error Message vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
ibm CWE-209
4.3
2024-07-26 CVE-2024-40689 SQL Injection vulnerability in IBM products
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2024-07-24 CVE-2024-37533 Privacy Violation vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine.
low complexity
ibm CWE-359
4.6
2024-07-12 CVE-2024-40690 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2023-50964 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2024-28794 Cross-site Scripting vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2024-06-30 CVE-2023-50952 Server-Side Request Forgery (SSRF) vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 is vulnerable to server-side request forgery (SSRF).
network
low complexity
ibm CWE-918
5.4
2024-06-30 CVE-2023-50953 Information Exposure Through an Error Message vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
network
low complexity
ibm CWE-209
4.3