First published: Wed Apr 23 2025(Updated: )
IBM InfoSphere DataStage Flow Designer transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Server | ||
IBM InfoSphere Information Server | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25046 is classified as a high-severity vulnerability due to its potential for exposing sensitive information.
To fix CVE-2025-25046, apply the available patch provided by IBM for InfoSphere Information Server version 11.7.
CVE-2025-25046 affects IBM InfoSphere Information Server version 11.7 and earlier.
CVE-2025-25046 transmits sensitive information via URL or query parameters.
CVE-2025-25046 is vulnerable to man-in-the-middle attacks that could expose sensitive information.