IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.
Advisories

No advisories yet.

Fixes

Solution

ProductVersion(s)APARRemediationIBM InfoSphere Information Server11.7.0.0 to 11.7.1.6 DT461542 https://www.ibm.com/mysupport/s/defect/aCIgJ0000009sNl/dt461542 --Apply IBM InfoSphere Information Server version  11.7.1.0 https://www.ibm.com/support/pages/node/878310   --Apply IBM InfoSphere Information Server version  11.7.1.6 https://www.ibm.com/support/pages/node/7182872 --Apply IBM InfoSphere Information Server  11.7.1.6 Service pack 2 https://www.ibm.com/support/pages/node/7260779


Workaround

Workarounds and Mitigations On the Microservices tier, change the file permissions: - cd </INSTALL_PATH/ugdockerfiles> - chmod 0600 uginfo.rsp - chmod 0600 inventory.yaml

History

Wed, 25 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.
Title IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password
First Time appeared Ibm
Ibm infosphere Information Server
Weaknesses CWE-256
CPEs cpe:2.3:a:ibm:infosphere_information_server:11.7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_information_server:11.7.1.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Information Server
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-03-25T20:25:21.329Z

Reserved: 2025-04-15T21:16:44.888Z

Link: CVE-2025-36258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-25T21:16:24.917

Modified: 2026-03-25T21:16:24.917

Link: CVE-2025-36258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T21:46:09Z

Weaknesses