IBM Product Security Update Advisory (CVE-2025-36258)

IBM Product Security Update Advisory (CVE-2025-36258)

overview

We have released security updates that address vulnerabilities in IBM products. users of affected products are encouraged to update to the latest version.

affected products

CVE-2025-36258

InfoSphere Information Server Versions: 11.7.0.0 and later and 11.7.1.6 and earlier

resolved Vulnerabilities

Vulnerability in IBM InfoSphere Information Server storing passwords in clear text (CVE-2025-36258)

vulnerability patches

Vulnerability patches have been made available in the latest update. please follow the instructions on the reference site to update to the latest version of the vulnerability patch.

CVE-2025-36258

InfoSphere Information Server version: 11.7.1.0
InfoSphere Information Server version: 11.7.1.6
InfoSphere Information Server Version: 11.7.1.6 Service pack 2

references

[1] Security Bulletin: IBM InfoSphere Information Server is vulnerable due to plaintext storage of a password (CVE-2025-36258)
https://www.ibm.com/support/pages/node/7266489