CVE Vulnerabilities

CVE-2025-25046

Cleartext Transmission of Sensitive Information

Published: Apr 23, 2025 | Modified: Aug 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM InfoSphere Information Server 11.7 DataStage Flow Designer 

transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Infosphere_information_server Ibm 11.7 (including) 11.7 (including)

Potential Mitigations

References