CVE-2025-36245: IBM InfoSphere Information Server command execution
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
Other sources
IBM InfoSphere Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36245?
CVE-2025-36245 is rated as a high severity vulnerability due to its potential to allow authenticated users to execute arbitrary commands with elevated privileges.
How do I fix CVE-2025-36245?
To remediate CVE-2025-36245, users should apply the latest security patches provided by IBM for InfoSphere Information Server version 11.7.0.0 through 11.7.1.6.
Who is affected by CVE-2025-36245?
All authenticated users of IBM InfoSphere Information Server versions 11.7.0.0 to 11.7.1.6 are affected by CVE-2025-36245.
What types of attacks can CVE-2025-36245 enable?
CVE-2025-36245 can enable authenticated users to execute arbitrary commands on the system, leading to potential data breaches and system compromise.
Is user interaction required for CVE-2025-36245 to be exploited?
No, CVE-2025-36245 can be exploited by authenticated users without any additional user interaction.