Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-12531


IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.


Published

2025-11-03T20:17:06.247

Last Modified

2025-11-05T15:16:17.020

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm infosphere_information_server ≤ 11.7.1.6 Yes

References