Description
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
Published: 2026-06-30
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 permits an attacker to disclose confidential data by interacting with the DataStage Flow Designer application. The weakness enables exposure of information that should be protected, resulting in a breach of confidentiality for sensitive data stored within the application. The referenced CWE-200 classifies the flaw as an information disclosure vulnerability.

Affected Systems

The issue affects IBM’s InfoSphere Information Server product line, specifically versions 11.7.0.0 up to and including 11.7.1.6. Users deploying these versions of the DataStage Flow Designer component are at risk unless they upgrade to a patched release.

Risk and Exploitability

The KEV field indicates that this vulnerability is not listed in the CISA KEV catalog. The CVSS score of 3.5 indicates a low overall severity, and the EPSS score is not available, suggesting limited data on exploitation likelihood. The description does not disclose the exact attack vector; it is inferred that a user with valid authentication to the application could exploit the flaw to access protected data. No additional conditions or privileges beyond those required to use the affected component are specified.

Generated by OpenCVE AI on June 30, 2026 at 20:51 UTC.

Remediation

Vendor Solution

IBM InfoSphere Information Server11.7.0.0 to 11.7.1.6DT471579--Apply IBM InfoSphere Information Server version 11.7.1.0--Apply IBM InfoSphere Information Server version 11.7.1.6--Apply IBM InfoSphere Information Server 11.7.1.6 Service pack 3


OpenCVE Recommended Actions

  • Apply IBM InfoSphere Information Server version 11.7.1.0
  • Apply IBM InfoSphere Information Server version 11.7.1.6
  • Apply IBM InfoSphere Information Server 11.7.1.6 Service pack 3

Generated by OpenCVE AI on June 30, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
Title IBM DataStage Flow Designer application is affected by an information disclosure vulnerability
First Time appeared Ibm
Ibm infosphere Information Server
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:infosphere_information_server:11.7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:11.7.1.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Information Server
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Infosphere Information Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-06-30T20:09:38.102Z

Reserved: 2026-05-28T12:49:17.163Z

Link: CVE-2026-9836

cve-icon Vulnrichment

Updated: 2026-06-30T20:09:32.562Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T01:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor