Sensitive Information Disclosure in IBM InfoSphere Information Server
CVE-2025-14808

3.1LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 March 2026

What is CVE-2025-14808?

A vulnerability exists in IBM InfoSphere Information Server that may allow an attacker to capture sensitive information from the query string using the HTTP GET request method. This exposure could be exploited through man-in-the-middle techniques, facilitating unauthorized access to confidential data. It is crucial that users of affected versions take immediate steps to apply patches and mitigate the risks associated with this vulnerability.

Affected Version(s)

InfoSphere Information Server 11.7.0.0 <= 11.7.1.6

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.