CVE Vulnerabilities

CVE-2025-25046

Cleartext Transmission of Sensitive Information

Published: Apr 23, 2025 | Modified: Aug 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM InfoSphere Information Server 11.7 DataStage Flow Designer 

transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Infosphere_information_serverIbm11.7 (including)11.7 (including)

Potential Mitigations

References