CVE-2025-25046

CVSS 3.1 Score 3.7 of 10 (low)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 319

Summary

CVE-2025-25046 is a vulnerability affecting IBM InfoSphere Information Server 11.7's DataStage Flow Designer. This issue allows unauthorized actors to intercept and access sensitive information transmitted via URL or query parameters using man-in-the-middle techniques. Successful exploitation could lead to confidential data exposure, potentially leading to serious security consequences. IBM strongly recommends implementing security measures, such as secure communications protocols and network encryption, to mitigate this risk. IBM is actively working on a patch to address this vulnerability and urges users to apply it as soon as it becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Infosphere Information Server

Affected Vendors

  • IBM