CVE-2016-9000: IBM InfoSphere Datastage
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker could use this vulnerability to conduct clickjacking or other client-side browser attacks.
Affected products
- IBM InfoSphere Datastage: version 8.7 only; version 9.1 only; version 11.3 only; version 11.5 only
- IBM InfoSphere Information Server On Cloud: version 11.5 only
Published 2017-02-01. Last modified 2026-06-17.