Impact
A vulnerability in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 permits an attacker to disclose confidential data by interacting with the DataStage Flow Designer application. The weakness enables exposure of information that should be protected, resulting in a breach of confidentiality for sensitive data stored within the application. The referenced CWE-200 classifies the flaw as an information disclosure vulnerability.
Affected Systems
The issue affects IBM’s InfoSphere Information Server product line, specifically versions 11.7.0.0 up to and including 11.7.1.6. Users deploying these versions of the DataStage Flow Designer component are at risk unless they upgrade to a patched release.
Risk and Exploitability
The KEV field indicates that this vulnerability is not listed in the CISA KEV catalog. The CVSS score of 3.5 indicates a low overall severity, and the EPSS score is not available, suggesting limited data on exploitation likelihood. The description does not disclose the exact attack vector; it is inferred that a user with valid authentication to the application could exploit the flaw to access protected data. No additional conditions or privileges beyond those required to use the affected component are specified.
OpenCVE Enrichment