First published: Mon Jul 17 2023(Updated: )
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Information Steward | <=11.7 | |
SAP Information Steward | =11.7 | |
IBM AIX | ||
Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35898 is a vulnerability in IBM InfoSphere Information Server 11.7 that allows an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer.
An authenticated user can exploit CVE-2023-35898 by leveraging the insecure security configuration in InfoSphere Data Flow Designer to obtain sensitive information.
CVE-2023-35898 has a severity score of 6.5, which is considered medium.
To fix CVE-2023-35898, apply the patch provided by IBM for InfoSphere Information Server 11.7 using the following link: [https://www.ibm.com/support/pages/node/878310](https://www.ibm.com/support/pages/node/878310).
You can find more information about CVE-2023-35898 on the following pages: [IBM Support Page](https://www.ibm.com/support/pages/node/7009205) and [IBM X-Force ID](https://exchange.xforce.ibmcloud.com/vulnerabilities/259352).