PT-2025-17674 · Ibm · Ibm Infosphere Information Server

Published

2025-04-23

·

Updated

2025-07-08

·

CVE-2025-25045

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Information Server version 11.7
Description The issue allows an authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.
Recommendations For IBM InfoSphere Information Server version 11.7, consider restricting access to detailed technical error messages to minimize the risk of information disclosure until a patch is available.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-06855
CVE-2025-25045

Affected Products

Ibm Infosphere Information Server