PT-2025-26982 · Ibm · Ibm Infosphere Information Server

CVE-2025-36034

·

Published

2025-06-26

·

Updated

2025-08-14

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IBM InfoSphere Information Server version 11.7
Description: The issue discloses sensitive user information in API requests in clear text, which could be intercepted using man-in-the-middle techniques.
Recommendations: For IBM InfoSphere Information Server version 11.7, consider implementing encryption for API requests to protect sensitive user information. As a temporary workaround, restrict access to sensitive data and API endpoints to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-36034

Affected Products

Ibm Infosphere Information Server