Description
IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-03-25
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting leading to credential disclosure
Action: Patch
AI Analysis

Impact

A business‑grade instance of IBM Infosphere Information Server releases 11.7.0.0 through 11.7.1.6 can store and display arbitrary JavaScript sent by a privileged user in the Web UI. The stored scripts execute in the browsers of other authenticated users, allowing exploitation of the normal user trust relationship and potentially revealing credentials or other sensitive data. This flaw is a typical stored cross‑site scripting vulnerability, classified as CWE‑79.

Affected Systems

IBM’s InfoSphere Information Server product is affected, specifically versions 11.7.0.0 up to 11.7.1.6 inclusive. The vulnerability is tied to the Web UI component of the product and applies regardless of the underlying operating system. Users running any of these versions should consider themselves at risk.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate risk with limited access requirements. EPSS is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting low widespread exploitation probability. Attack execution requires a privileged user with access to the Web UI and the ability to create or edit content that will be stored. Once a privileged user injects malicious code, other authenticated users’ browsers will run it, so the attack vector is primarily internal and requires existing credentials or compromised accounts within the same environment.

Generated by OpenCVE AI on March 26, 2026 at 19:51 UTC.

Remediation

Vendor Solution

Remediation/Fixes Product Version(s) APAR Remediation IBM InfoSphere Information Server 11.7.0.0 to 11.7.1.6 DT458255 DT459618 --Apply IBM InfoSphere Information Server version 11.7.1.0 --Apply IBM InfoSphere Information Server version 11.7.1.6 --Apply IBM InfoSphere Information Server 11.7.1.6 Service pack 2


OpenCVE Recommended Actions

  • Upgrade IBM InfoSphere Information Server to version 11.7.1.6 Service Pack 2

Generated by OpenCVE AI on March 26, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 28 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm aix
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 25 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Description IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM InfoSphere Information Server Cross-Site Scripting
First Time appeared Ibm
Ibm infosphere Information Server
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:infosphere_information_server:11.7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:11.7.1.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Information Server
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Aix Infosphere Information Server
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-27T19:39:21.362Z

Reserved: 2026-02-13T20:02:39.559Z

Link: CVE-2026-2485

cve-icon Vulnrichment

Updated: 2026-03-27T19:30:55.158Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T21:16:41.280

Modified: 2026-03-26T18:05:28.777

Link: CVE-2026-2485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:29:43Z

Weaknesses