Executive brief
IBM InfoSphere Information Server, a platform used for data integration and governance, is affected by a security flaw in its DataStage Flow Designer component. An attacker with access to the local network could potentially view sensitive information that they are not authorized to see. While the risk is rated as low, this could lead to the exposure of internal system details or configuration data.
Technical details
IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 contain an information disclosure vulnerability (CWE-200) within the DataStage Flow Designer application. The vulnerability allows a low-privileged attacker on the same adjacent network to gain unauthorized access to sensitive information. The attack vector is restricted to the adjacent network (AV:A) and requires low privileges (PR:L), with no user interaction required. IBM has released a fix (DT471579) which can be applied via updates to version 11.7.1.0 or 11.7.1.6 Service Pack 3.
Affected products
- IBM InfoSphere Information Server 11.7.0.0 - 11.7.1.6
Timeline
- 2026-06-26: advisory: Initial publication by IBM
- 2026-06-30: disclosed: NVD publication date