IBM InfoSphere Information Server
cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*
- 11.7
A path traversal vulnerability has been identified in IBM InfoSphere Information Server version 11.7. This vulnerability could allow a remote attacker to traverse directories on the system by sending a specially crafted URL request that includes 'dot dot' sequences. This could enable the attacker to view arbitrary files on the system.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the system.
Users can upgrade to InfoSphere Information Server version 11.7.1.0 or 11.7.1.5. For the most secure option, enable the IBM DataStage Flow Designer server with non-root administration. If only system files need protection, apply the InfoSphere DataStage Flow Designer security patch.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.