IBM InfoSphere Information Server Plaintext Credential Storage Vulnerability

Vulnerability

A vulnerability exists in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6, where user credentials and other sensitive information are stored in plaintext. This allows local users to read the information easily. The vulnerability is categorized under CWE-256, which pertains to the plaintext storage of passwords.

Impact

The vulnerability allows local users to access sensitive information, including user credentials, stored in plaintext.

Remediation

Users can upgrade to IBM InfoSphere Information Server versions 11.7.1.0, 11.7.1.6, or 11.7.1.6 Service Pack 2. For those on the Microservices tier, it's recommended to change the file permissions of 'uginfo.rsp' and 'inventory.yaml' to '0600'.

Added: Mar 25, 2026, 10:15 PM
Updated: Mar 25, 2026, 10:15 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
3.8
remediation
8.3
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.