Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25801 | IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques. |
Solution
InfoSphere Information Server, InfoSphere Information Server on Cloud 11.7.0.0 to 11.7.1.6 DT439751 --Apply InfoSphere Information Server version 11.7.1.0 --Apply InfoSphere Information Server version 11.7.1.6 --Apply InfoSphere DataStage Flow Designer security patch
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7237604 |
|
Thu, 26 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques. | |
| Title | IBM InfoSphere DataStage Flow Designer information disclosure | |
| First Time appeared |
Ibm
Ibm infosphere Information Server |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm infosphere Information Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-26T14:51:14.232Z
Reserved: 2025-04-15T21:16:09.684Z
Link: CVE-2025-36034
Updated: 2025-06-26T15:23:38.512Z
Status : Analyzed
Published: 2025-06-26T16:15:28.567
Modified: 2025-08-14T20:57:36.537
Link: CVE-2025-36034
No data.
OpenCVE Enrichment
No data.
EUVD