IBM InfoSphere Information Server Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6, specifically within the DataStage Flow Designer. This vulnerability could enable an attacker to perform malicious and unauthorized actions by exploiting the trust that the application has in the user.

Impact

Exploitation of this vulnerability could allow an attacker to execute unauthorized actions on behalf of a user that the application trusts.

Remediation

Users can upgrade to IBM InfoSphere Information Server versions 11.7.1.0, 11.7.1.6, or 11.7.1.6 Service Pack 2. Instructions for downloading these versions are available on the IBM Support website.

Added: Mar 25, 2026, 10:16 PM
Updated: Mar 25, 2026, 10:16 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.8
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.