Stored Cross-Site Scripting Vulnerability in IBM Infosphere Information Server
CVE-2026-2485
4.8MEDIUM
What is CVE-2026-2485?
IBM Infosphere Information Server versions 11.7.0.0 to 11.7.1.6 have a stored cross-site scripting vulnerability that enables a privileged user to inject arbitrary JavaScript code into the Web UI. This can compromise the application's intended functionality and potentially lead to unauthorized disclosure of user credentials during trusted sessions.
Affected Version(s)
InfoSphere Information Server 11.7.0.0 <= 11.7.1.6