IBM InfoSphere Information Server Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing sensitive information disclosure has been identified in IBM InfoSphere Information Server versions 11.7.0.0 prior to 11.7.1.6. This issue arises from the use of the HTTP GET method to process requests, which can expose sensitive information in the query string. Such data could be intercepted through man-in-the-middle techniques.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information transmitted in the query string of HTTP GET requests.

Remediation

Users can upgrade to IBM InfoSphere Information Server versions 11.7.1.0, 11.7.1.6, or 11.7.1.6 Service Pack 2 to address this vulnerability.

Added: Mar 25, 2026, 10:22 PM
Updated: Mar 25, 2026, 10:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.0
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.