IBM InfoSphere Information Server XML External Entity Vulnerability Allowing Sensitive Information Retrieval

Vulnerability

A XML External Entity (XXE) vulnerability has been identified in IBM InfoSphere Information Server versions 11.7.0.0 prior to 11.7.1.6. This vulnerability could allow attackers to retrieve sensitive information from the server.

Impact

Exploitation of this vulnerability could lead to unauthorized retrieval of sensitive information from the affected server.

Remediation

Users can upgrade to IBM InfoSphere Information Server versions 11.7.1.0, 11.7.1.5, or 11.7.1.6. Alternatively, apply the IBM InfoSphere Information Server security patch available through the IBM Support Fix Central.

Added: Mar 3, 2026, 9:20 PM
Updated: Mar 3, 2026, 9:57 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.