PT-2025-17675 · Ibm · Ibm Infosphere Information Server

CVE-2025-25046

·

Published

2025-04-23

·

Updated

2025-04-24

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Information Server version 11.7
Description The issue concerns the transmission of sensitive information via URL or query parameters, which could be exposed to an unauthorized actor using man-in-the-middle techniques.
Recommendations For IBM InfoSphere Information Server version 11.7, consider configuring the DataStage Flow Designer to use secure communication protocols, such as HTTPS, to encrypt sensitive information transmitted via URL or query parameters. As a temporary workaround, restrict access to sensitive data and limit the use of query parameters to minimize the risk of exposure.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06866
CVE-2025-25046

Affected Products

Ibm Infosphere Information Server