Infosphere Information Server

Vendor:

First CVE: Dec 9, 2009 · Active for 16 years

189
Total CVEs
More Total CVEs than 99% of tracked products
11.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Infosphere Information Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2009
16 years ago
Most Recent CVE
Jun 30, 2026
27 days ago

CVE Severity & Scoring

Infosphere Information Server189 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local14 (7.4%)
Network141 (74.6%)
Unknown30 (15.9%)
Physical1 (0.5%)
Adjacent Network3 (1.6%)
Attack Complexity
Low149 (78.8%)
High10 (5.3%)
Unknown30 (15.9%)
User Interaction
None107 (56.6%)
Unknown30 (15.9%)
Required52 (27.5%)
Privileges Required
Low91 (48.1%)
High4 (2.1%)
None64 (33.9%)
Unknown30 (15.9%)

Top CVEs

Signals from CVEs in this product scope (189 CVEs).

189 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
Jun 30, 20267.532NONO
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
Nov 16, 20229.831NONO
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation
Nov 3, 20229.831NONO
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285.
May 22, 20239.830NONO
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m
May 19, 20239.830NONO
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m
Jun 6, 20229.830NONO
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By pe
Jul 9, 20208.830NONO
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability
Nov 3, 20229.129NONO
IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This
Jan 26, 20219.829NONO
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit
Nov 3, 20259.128NONO

Exploit Exposure

Signals from CVEs in this product scope (189 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (189 CVEs).

Media Mentions

Signals from CVEs in this product scope (189 CVEs).

Top CNAs Publishing CVEs For Infosphere Information Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1.275.00.9%00
9.1.0.164.90.9%00
9.1305.91.0%00
8.7.0.284.81.0%00
8.7.0.184.81.0%00
8.7295.10.9%00
8.5.0.394.71.1%00
8.5.0.2194.91.0%00
8.5.0.1215.10.9%00
8.5295.41.0%00
8.1225.31.0%00
8.034.10.9%00
11.7.118.30.6%00
11.7.0.225.70.6%00
11.7.0.125.70.6%00
11.7966.30.7%00
11.5.018.84.5%00
11.5276.51.3%00
11.3.134.41.0%00
11.3.018.84.5%00