CVE-2025-36258: IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.
Other sources
IBM InfoSphere Information Server product stores user credentials and other sensitive information in plain text which can be read by a local user.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36258?
CVE-2025-36258 is considered a high-severity vulnerability due to the insecure storage of sensitive credentials in plaintext.
How do I fix CVE-2025-36258?
To fix CVE-2025-36258, apply the relevant patches released by IBM for versions 11.7.0.0 through 11.7.1.6.
What are the risks associated with CVE-2025-36258?
The risks associated with CVE-2025-36258 include unauthorized access to sensitive information and potential data breaches.
Which versions of IBM InfoSphere Information Server are affected by CVE-2025-36258?
CVE-2025-36258 affects IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6.
What type of vulnerability is CVE-2025-36258?
CVE-2025-36258 is an information disclosure vulnerability due to the insecure handling of user credentials.