Impact
A vulnerability in IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 allows an attacker to forge requests that the target system will accept as legitimate. By leveraging the web interface of the DataStage Flow Designer component, an adversary could deliver authenticated requests on behalf of a user, potentially modifying data or executing actions without authorization.
Affected Systems
IBM Web-based product Information Server, specifically the InfoSphere DataStage Flow Designer component. Affected releases include versions 11.7.0.0 up to and including 11.7.1.6 across supported operating systems such as AIX, Linux, and Windows.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate severity. Exploit probability is low, with an EPSS score below 1%. The vulnerability is not listed in the CISA KEV catalog. Attackers likely exploit the web interface remotely by sending crafted cross‑site requests; successful exploitation would enable unauthorized actions performed in the context of a trusted user, potentially compromising integrity and confidentiality of managed data.
OpenCVE Enrichment