IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

Project Subscriptions

Vendors Products
Infosphere Information Server Subscribe
Infosphere Information Server On Cloud Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-16576 IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
Fixes

Solution

InfoSphere Information Server, InfoSphere Information Server on Cloud 11.7 DT423714 --Apply InfoSphere Information Server version 11.7.1.0 --Apply InfoSphere Information Server version 11.7.1.6 --Apply InfoSphere DataStage security patch


Workaround

No workaround given by the vendor.

History

Mon, 09 Jun 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm infosphere Information Server On Cloud
CPEs cpe:2.3:a:ibm:infosphere_information_server_on_cloud:11.7:*:*:*:*:*:*:*
Vendors & Products Ibm infosphere Information Server On Cloud

Mon, 02 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 01 Jun 2025 11:45:00 +0000

Type Values Removed Values Added
Description IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
Title IBM InfoSphere Information Server information disclosure
First Time appeared Ibm
Ibm infosphere Information Server
Weaknesses CWE-312
CPEs cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Information Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-08-26T14:54:42.793Z

Reserved: 2025-02-20T15:32:19.936Z

Link: CVE-2025-1499

cve-icon Vulnrichment

Updated: 2025-06-02T03:16:45.471Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-01T12:15:24.230

Modified: 2025-06-09T18:08:54.680

Link: CVE-2025-1499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses