CVE-2025-36034: IBM InfoSphere DataStage Flow Designer information disclosure
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36034?
CVE-2025-36034 has a high severity due to the potential exposure of sensitive user information.
How do I fix CVE-2025-36034?
To mitigate CVE-2025-36034, ensure that API requests are encrypted and apply any relevant patches from IBM as they become available.
What type of data is exposed in CVE-2025-36034?
CVE-2025-36034 exposes sensitive user information in API requests transmitted in clear text.
What are the potential risks of CVE-2025-36034?
The risks associated with CVE-2025-36034 include unauthorized access to sensitive information through man-in-the-middle attacks.
Which versions of IBM InfoSphere are affected by CVE-2025-36034?
IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 is affected by CVE-2025-36034.