transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12154 | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7231333 |
|
Tue, 12 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:-:*:*:* |
Thu, 24 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Apr 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM InfoSphere Information Server 11.7 DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques. | |
| Title | IBM InfoSphere Information Server information disclosure | |
| First Time appeared |
Ibm
Ibm infosphere Information Server |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm infosphere Information Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-28T15:04:09.033Z
Reserved: 2025-02-01T15:07:06.692Z
Link: CVE-2025-25046
Updated: 2025-04-24T14:53:50.256Z
Status : Analyzed
Published: 2025-04-23T23:15:16.357
Modified: 2025-08-12T17:58:41.017
Link: CVE-2025-25046
No data.
OpenCVE Enrichment
No data.
EUVD