CVE-2025-14810: IBM InfoSphere Information Server is vulnerable due to insufficient session expiration
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CWE: CWE-613: Insufficient Session Expiration CVSS Source: IBM CVSS Base score: 6.3 CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
Other sources
InfoSphere Information Server does not invalidate a session after privileges have been modified which could allow an authenticated user to retain access to sensitive information.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14810?
CVE-2025-14810 has a significant severity level due to its potential to expose sensitive information to authenticated users.
How do I fix CVE-2025-14810?
To fix CVE-2025-14810, apply the available patch provided by IBM for InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6.
Who is affected by CVE-2025-14810?
CVE-2025-14810 affects users of IBM InfoSphere Information Server version 11.7.0.0 to 11.7.1.6.
What is the impact of CVE-2025-14810?
The impact of CVE-2025-14810 includes the risk of unauthorized access to sensitive information due to inadequate session expiration after privilege changes.
Is CVE-2025-14810 a remote or local vulnerability?
CVE-2025-14810 is considered a local vulnerability that requires authentication to exploit.