PT-2026-28126 · Ibm · Ibm Infosphere Information Server

Published

2026-03-25

·

Updated

2026-03-26

·

CVE-2025-14807

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6
Description The software is susceptible to HTTP header injection due to inadequate input validation of the HOST headers. This could enable an attacker to perform various attacks against the system, including cross-site scripting, cache poisoning, or session hijacking.
Recommendations Update to a version later than 11.7.1.6.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-14807

Affected Products

Ibm Infosphere Information Server