CVE-2025-14974: IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).
Other sources
IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference (IDOR).
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14974?
CVE-2025-14974 has a high severity due to the risk of unauthorized access to sensitive information.
How do I fix CVE-2025-14974?
To mitigate CVE-2025-14974, users should update to a version of IBM InfoSphere Information Server beyond 11.7.1.6.
What does CVE-2025-14974 vulnerability affect?
CVE-2025-14974 affects IBM InfoSphere Information Server versions 11.7.0.0 to 11.7.1.6 due to Insecure Direct Object Reference.
Can CVE-2025-14974 be exploited remotely?
Yes, CVE-2025-14974 can potentially be exploited remotely by an attacker to access restricted information.
Is there an official patch for CVE-2025-14974?
Yes, IBM has released a patch for CVE-2025-14974 that users are advised to implement promptly.