IBM InfoSphere Information Server
cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*
- 11.7
A sensitive information disclosure vulnerability has been identified in IBM InfoSphere Information Server version 11.7. This vulnerability allows authenticated users to access sensitive information through detailed technical error messages returned in response to requests. The disclosed information could potentially be exploited in further attacks against the system.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, which could be used to facilitate additional attacks on the system.
Users can upgrade to IBM InfoSphere Information Server version 11.7.1.0 or 11.7.1.6. Additionally, a security patch for IBM DataStage Flow Designer is available. Note that this security fix impacts the usage of the DataStage Flow Designer APIs, which require explicit login and logout calls before and after other API invocations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.