CVE-2025-1138
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-548
- Published
- 2025-05-15
- Last modified
- 2026-03-13
Affected products
- IBM InfoSphere Information Server
Weakness type
Related vulnerabilities
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory...
- CVE-2026-41933 — Vvveb < 1.0.8.3 Directory Listing Information Disclosure
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2023-38265 — Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]
- CVE-2020-36921 — RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability
- CVE-2022-50788 — SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory