CVE-2023-23472: IBM InfoSphere Information Server information disclosure
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
Other sources
IBM InfoSphere DataStage Flow Designer could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23472?
CVE-2023-23472 has a significant severity rating, as it can allow authenticated users to access sensitive information.
How do I fix CVE-2023-23472?
To fix CVE-2023-23472, apply the available patches from IBM for InfoSphere Information Server version 11.7.
Who is affected by CVE-2023-23472?
CVE-2023-23472 affects authenticated users of IBM InfoSphere DataStage Flow Designer in version 11.7.
What type of information is exposed in CVE-2023-23472?
CVE-2023-23472 could allow an authenticated user to obtain sensitive information that assists in further attacks.
Is there a workaround for CVE-2023-23472 until a patch is applied?
IBM has not specified any workarounds for CVE-2023-23472, so it is recommended to apply the patch as soon as possible.