Sensitive Credential Exposure in IBM InfoSphere Information Server
CVE-2024-7577

4.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 March 2025

Summary

IBM InfoSphere Information Server 11.7 has a vulnerability that may allow sensitive user credentials to be disclosed from log files during the initial installation process. This exposure poses a significant risk to user data integrity and confidentiality, underscoring the necessity for vigilant security practices. It’s crucial for users to review their installation configurations and adhere to best practices to mitigate potential risks associated with this vulnerability.

Affected Version(s)

InfoSphere Information Server 11.7

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.