PT-2025-44790 · Ibm · Ibm Infosphere Information Server

Published

2025-11-03

·

Updated

2025-11-04

·

CVE-2025-12531

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6
Description IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 are susceptible to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could potentially exploit this issue to disclose sensitive information or exhaust memory resources. An XML external entity (XXE) attack occurs when an XML parser processes XML input that contains a reference to an external entity. This can allow an attacker to include arbitrary files, potentially exposing sensitive data or causing a denial-of-service condition.
Recommendations Update IBM InfoSphere Information Server to a version later than 11.7.1.6.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-12531

Affected Products

Ibm Infosphere Information Server