CVE-2026-2485: IBM InfoSphere Information Server Cross-Site Scripting
IBM Infosphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
Infosphere Information Server is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2485?
CVE-2026-2485 is a serious vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2026-2485?
To fix CVE-2026-2485, apply the latest patch provided by IBM for InfoSphere Information Server.
What versions of InfoSphere Information Server are affected by CVE-2026-2485?
CVE-2026-2485 affects IBM InfoSphere Information Server versions from 11.7.0.0 to 11.7.1.6.
Who can exploit CVE-2026-2485?
CVE-2026-2485 can be exploited by a privileged user who can embed arbitrary JavaScript code into the Web UI.
What impact does CVE-2026-2485 have on my system?
CVE-2026-2485 can compromise the integrity of the web application's functionality and user sessions through cross-site scripting.