Description
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
Published: 2026-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain an XML external entity injection flaw that allows an attacker to read data that the server has access to. The flaw is a classic XXE vulnerability (CWE-611) and can expose confidential configuration files, credentials, or other sensitive data stored on the system. The vulnerability can be triggered by submitting maliciously crafted XML to any endpoint that parses XML input without proper validation.

Affected Systems

The affected products are IBM InfoSphere Information Server. Users of version 11.7.0.0 up to and including 11.7.1.6 are impacted. In particular, IBM provides remediation steps for all releases within this range, recommending upgrades to 11.7.1.0, 11.7.1.5, or 11.7.1.6, or the application of the general security patch via IBM Fix Central.

Risk and Exploitability

The CVSS base score is 7.1, indicating high severity, while the EPSS score is very low (<1%) but non‑zero, suggesting that attacks may not be widespread yet but are possible. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted XML documents to the InfoSphere server; no local privilege escalation is required, and an attacker with network access to the server or a user able to submit XML data can obtain confidential information. The risk is significant for systems that process untrusted XML input and may host sensitive data.

Generated by OpenCVE AI on April 16, 2026 at 13:58 UTC.

Remediation

Vendor Solution

ProductVersion(s)APARRemediationIBM InfoSphere Information Server11.7.0.0 to 11.7.1.6 DT461311 https://www.ibm.com/mysupport/s/defect/aCIgJ0000009mNB/dt461311 --Apply IBM InfoSphere Information Server version 11.7.1.0 https://www.ibm.com/support/pages/node/878310   --Apply IBM InfoSphere Information Server version 11.7.1.5 https://www.ibm.com/support/pages/node/7156680  or 11.7.1.6 https://www.ibm.com/support/pages/node/7182872 --Apply IBM InfoSphere Information Server security patch https://www.ibm.com/support/fixcentral/quickorder


OpenCVE Recommended Actions

  • Upgrade to IBM InfoSphere Information Server version 11.7.1.0 or later, including the newer 11.7.1.5 and 11.7.1.6 releases, as documented by IBM.
  • Apply the IBM InfoSphere Information Server security patch available through IBM Fix Central to ensure the latest protection against XXE exploitation.
  • Configure the XML parser to disallow external entity resolution and validate all XML input against a whitelist or schema to prevent future XXE attacks.

Generated by OpenCVE AI on April 16, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 05 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*:*

Tue, 03 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
Title IBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerability
First Time appeared Ibm
Ibm infosphere Information Server
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:infosphere_information_server:11.7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:11.7.1.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Information Server
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Ibm Infosphere Information Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-03T20:56:58.121Z

Reserved: 2026-01-28T20:19:15.181Z

Link: CVE-2026-1567

cve-icon Vulnrichment

Updated: 2026-03-03T20:52:52.580Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-03T21:15:57.617

Modified: 2026-03-05T21:29:11.027

Link: CVE-2026-1567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T14:00:19Z

Weaknesses