IBM InfoSphere Information Server
cpe:2.3:a:ibm:infosphere_information_server:*:*:*:*:*:*:*
- >= 11.7.0.0, <= 11.7.1.6
A cross-site request forgery (CSRF) vulnerability has been identified in IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6, specifically within the DataStage Flow Designer. This vulnerability could enable an attacker to perform malicious and unauthorized actions by exploiting the trust that the application has in the user.
Exploitation of this vulnerability could allow an attacker to execute unauthorized actions on behalf of a user that the application trusts.
Users can upgrade to IBM InfoSphere Information Server versions 11.7.1.0, 11.7.1.6, or 11.7.1.6 Service Pack 2. Instructions for downloading these versions are available on the IBM Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.