DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-36258

High
Low Medium High Critical
7.1
CVSS Score
Published: Mar 25, 2026
Last Modified: Mar 26, 2026

Vulnerability Description

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
L
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
C
Confidentiality
H
Integrity
N
Availability
N

Known Affected Software

4 configuration(s) from 1 vendor(s)

infosphere_information_server
Version:
11.7
CPE:
cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:*
infosphere_information_server
Version:
11.7.0.1
CPE:
cpe:2.3:a:ibm:infosphere_information_server:11.7.0.1:*:*:*:*:*:*:*
infosphere_information_server
Version:
11.7.0.2
CPE:
cpe:2.3:a:ibm:infosphere_information_server:11.7.0.2:*:*:*:*:*:*:*
infosphere_information_server
Version:
11.7.1
CPE:
cpe:2.3:a:ibm:infosphere_information_server:11.7.1:*:*:*:*:*:*:*
This vulnerability affects 4 software configuration(s). Ensure you patch all affected systems.

Severity Details

7.1
out of 10.0
High

Weakness Type (CWE)

CWE-256

Plaintext Storage of a Password

Description
The product stores a password in plaintext within resources such as memory or files.
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Base

Key Information

Published Date
March 25, 2026