CVE-2025-1138: IBM Information Server information disclosure
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.
Other sources
IBM InfoSphere Information Server could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing,
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1138?
CVE-2025-1138 has been classified as a medium severity vulnerability.
How does CVE-2025-1138 affect IBM InfoSphere Information Server?
CVE-2025-1138 allows an authenticated user to access sensitive directories which may lead to further attacks.
What are the potential impacts of exploiting CVE-2025-1138?
Exploitation of CVE-2025-1138 could lead to unauthorized access to sensitive information within IBM InfoSphere Information Server.
How do I fix CVE-2025-1138?
To mitigate CVE-2025-1138, ensure all configurations restrict directory listings and apply any available security patches provided by IBM.
What versions of IBM InfoSphere Information Server are affected by CVE-2025-1138?
CVE-2025-1138 affects IBM InfoSphere Information Server 11.7.