IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Subscriptions

Vendors Products
Infosphere Information Server Subscribe
Linux Kernel Subscribe
Microsoft Subscribe
Windows Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19079 IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Fixes

Solution

InfoSphere Information Server, InfoSphere Information Server on Cloud 11.7.0.0 to 11.7.1.6 DT422417 --Apply InfoSphere Information Server version 11.7.1.0 --Apply InfoSphere Information Server version 11.7.1.6 --Apply InfoSphere DataStage security patch --For InfoSphere DataStage Flow Designer, a security patch will be published subsequently.


Workaround

No workaround given by the vendor.

History

Tue, 08 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 25 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Jun 2025 03:15:00 +0000

Type Values Removed Values Added
Description IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title IBM InfoSphere Information Server SQL injection
First Time appeared Ibm
Ibm infosphere Information Server
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Information Server
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-26T17:50:24.914Z

Reserved: 2025-02-01T15:06:54.119Z

Link: CVE-2025-0966

cve-icon Vulnrichment

Updated: 2025-06-25T14:51:49.172Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-25T03:15:26.580

Modified: 2025-07-08T14:55:16.967

Link: CVE-2025-0966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses