IBM InfoSphere Information Server Directory Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in IBM InfoSphere Information Server version 11.7. This vulnerability could allow a remote attacker to traverse directories on the system by sending a specially crafted URL request that includes 'dot dot' sequences. This could enable the attacker to view arbitrary files on the system.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the system.

Remediation

Users can upgrade to InfoSphere Information Server version 11.7.1.0 or 11.7.1.5. For the most secure option, enable the IBM DataStage Flow Designer server with non-root administration. If only system files need protection, apply the InfoSphere DataStage Flow Designer security patch.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.