CVE-2025-1138: IBM InfoSphere Information Server

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.

Affected products

  • IBM InfoSphere Information Server: version 11.7 only
  • IBM InfoSphere Information Server On Cloud: version 11.7 only

Published 2025-05-15. Last modified 2026-06-17.