First published: Mon Jul 17 2023(Updated: )
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.7 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Ibm Infosphere Information Server | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35898 is a vulnerability in IBM InfoSphere Information Server 11.7 that allows an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer.
An authenticated user can exploit CVE-2023-35898 by leveraging the insecure security configuration in InfoSphere Data Flow Designer to obtain sensitive information.
CVE-2023-35898 has a severity score of 6.5, which is considered medium.
To fix CVE-2023-35898, apply the patch provided by IBM for InfoSphere Information Server 11.7 using the following link: [https://www.ibm.com/support/pages/node/878310](https://www.ibm.com/support/pages/node/878310).
You can find more information about CVE-2023-35898 on the following pages: [IBM Support Page](https://www.ibm.com/support/pages/node/7009205) and [IBM X-Force ID](https://exchange.xforce.ibmcloud.com/vulnerabilities/259352).