Infosphere Information Server
Vendor:
First CVE: Dec 9, 2009 · Active for 16 years
189
Total CVEs
More Total CVEs than 99% of tracked products
11.8
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Infosphere Information Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2009
16 years ago
Most Recent CVE
Jun 30, 2026
27 days ago
CVE Severity & Scoring
Infosphere Information Server189 CVEs
64%
23%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (7.4%)
Network141 (74.6%)
Unknown30 (15.9%)
Physical1 (0.5%)
Adjacent Network3 (1.6%)
Attack Complexity
Low149 (78.8%)
High10 (5.3%)
Unknown30 (15.9%)
User Interaction
None107 (56.6%)
Unknown30 (15.9%)
Required52 (27.5%)
Privileges Required
Low91 (48.1%)
High4 (2.1%)
None64 (33.9%)
Unknown30 (15.9%)
Top CVEs
Signals from CVEs in this product scope (189 CVEs).
189 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9836HIGH IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. | Jun 30, 2026 | 7.5 | 32 | NO | NO |
CVE-2022-40752CRITICAL IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. | Nov 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-22425CRITICAL "IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation | Nov 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-32336CRITICAL IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserialization in an RMI service. IBM X-Force ID: 255285. | May 22, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-47984CRITICAL IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m | May 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-31768CRITICAL IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, m | Jun 6, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-4305HIGH IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By pe | Jul 9, 2020 | 8.8 | 30 | NO | NO |
CVE-2022-40747CRITICAL "IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability | Nov 3, 2022 | 9.1 | 29 | NO | NO |
CVE-2020-27583CRITICAL IBM InfoSphere Information Server 8.5.0.0 is affected by deserialization of untrusted data which could allow remote unauthenticated attackers to execute arbitrary code. NOTE: This | Jan 26, 2021 | 9.8 | 29 | NO | NO |
CVE-2025-12531CRITICAL IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit | Nov 3, 2025 | 9.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (189 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (189 CVEs).
Media Mentions
Signals from CVEs in this product scope (189 CVEs).
Top CNAs Publishing CVEs For Infosphere Information Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.2 | 7 | 5.0 | 0.9% | 0 | 0 |
| 9.1.0.1 | 6 | 4.9 | 0.9% | 0 | 0 |
| 9.1 | 30 | 5.9 | 1.0% | 0 | 0 |
| 8.7.0.2 | 8 | 4.8 | 1.0% | 0 | 0 |
| 8.7.0.1 | 8 | 4.8 | 1.0% | 0 | 0 |
| 8.7 | 29 | 5.1 | 0.9% | 0 | 0 |
| 8.5.0.3 | 9 | 4.7 | 1.1% | 0 | 0 |
| 8.5.0.2 | 19 | 4.9 | 1.0% | 0 | 0 |
| 8.5.0.1 | 21 | 5.1 | 0.9% | 0 | 0 |
| 8.5 | 29 | 5.4 | 1.0% | 0 | 0 |
| 8.1 | 22 | 5.3 | 1.0% | 0 | 0 |
| 8.0 | 3 | 4.1 | 0.9% | 0 | 0 |
| 11.7.1 | 1 | 8.3 | 0.6% | 0 | 0 |
| 11.7.0.2 | 2 | 5.7 | 0.6% | 0 | 0 |
| 11.7.0.1 | 2 | 5.7 | 0.6% | 0 | 0 |
| 11.7 | 96 | 6.3 | 0.7% | 0 | 0 |
| 11.5.0 | 1 | 8.8 | 4.5% | 0 | 0 |
| 11.5 | 27 | 6.5 | 1.3% | 0 | 0 |
| 11.3.1 | 3 | 4.4 | 1.0% | 0 | 0 |
| 11.3.0 | 1 | 8.8 | 4.5% | 0 | 0 |