CVE-2025-0966: IBM InfoSphere Information Server SQL injection
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM InfoSphere Information Server vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0966?
CVE-2025-0966 is rated as a critical severity vulnerability due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2025-0966?
To fix CVE-2025-0966, apply the latest patches provided by IBM for InfoSphere Information Server 11.7.
What type of vulnerability is CVE-2025-0966?
CVE-2025-0966 is a SQL injection vulnerability that allows attackers to manipulate SQL queries.
Who is affected by CVE-2025-0966?
CVE-2025-0966 affects all versions of IBM InfoSphere Information Server up to and including 11.7.
What could an attacker do with CVE-2025-0966?
An attacker exploiting CVE-2025-0966 could view, add, modify, or delete information in the back-end database.