CVE-2025-1499: IBM InfoSphere Information Server information disclosure
IBM InfoSphere DataStage stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
Other sources
IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1499?
CVE-2025-1499 has a medium severity rating due to its potential exposure of sensitive credential information.
How do I fix CVE-2025-1499?
To fix CVE-2025-1499, apply the recommended patch provided by IBM for InfoSphere Information Server 11.7.
Who is affected by CVE-2025-1499?
CVE-2025-1499 affects authenticated users of IBM InfoSphere Information Server versions up to and including 11.7.
What kind of information is exposed in CVE-2025-1499?
CVE-2025-1499 exposes database authentication credentials that are stored in cleartext.
Why is CVE-2025-1499 a concern for cybersecurity?
CVE-2025-1499 is a concern because it allows authenticated users to view sensitive credentials, potentially leading to unauthorized database access.