Session Management Flaw in IBM InfoSphere Information Server Affects User Access
CVE-2025-14810

6.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 March 2026

What is CVE-2025-14810?

IBM InfoSphere Information Server versions 11.7.0.0 to 11.7.1.6 contain a vulnerability that fails to invalidate user sessions after changes to user privileges. This oversight potentially allows authenticated users to maintain access to sensitive information even after their permissions have been modified. Proper session management is critical to protect data from unauthorized access, and this flaw highlights the importance of robust security measures in user session handling.

Affected Version(s)

InfoSphere Information Server 11.7.0.0 <= 11.7.1.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.