CVE-2025-12531: IBM InfoSphere Information Server
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected products
- IBM InfoSphere Information Server: from 11.7, up to and including 11.7.1.6
Published 2025-11-03. Last modified 2026-06-17.