CVE-2025-36422: IBM InfoSphere Information Server is vulnerable to cross-site request forgery
IBM InfoSphere DataStage Flow Designer is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36422?
CVE-2025-36422 has a medium severity rating due to its potential to allow unauthorized actions via cross-site request forgery.
How do I fix CVE-2025-36422?
To fix CVE-2025-36422, users should apply the available patches for IBM InfoSphere Information Server and IBM InfoSphere DataStage Flow Designer.
Which versions are affected by CVE-2025-36422?
CVE-2025-36422 affects IBM InfoSphere Information Server and IBM InfoSphere DataStage Flow Designer versions between 11.7.0.0 and 11.7.1.6.
What type of attack does CVE-2025-36422 allow?
CVE-2025-36422 allows cross-site request forgery attacks that could lead to unauthorized actions being executed by a trusted user.
Who is the vendor for CVE-2025-36422?
The vendor for CVE-2025-36422 is IBM, which develops the affected software products.