PT-2025-44790 · Ibm · Ibm Infosphere Information Server
Published
2025-11-03
·
Updated
2025-11-04
·
CVE-2025-12531
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6
Description
IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 are susceptible to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could potentially exploit this issue to disclose sensitive information or exhaust memory resources. An XML external entity (XXE) attack occurs when an XML parser processes XML input that contains a reference to an external entity. This can allow an attacker to include arbitrary files, potentially exposing sensitive data or causing a denial-of-service condition.
Recommendations
Update IBM InfoSphere Information Server to a version later than 11.7.1.6.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Infosphere Information Server