{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-36034","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2025-04-15T21:16:09.684Z","datePublished":"2025-06-26T15:14:10.478Z","dateUpdated":"2025-08-26T14:51:14.232Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:infosphere_information_server:11.7:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","product":"InfoSphere Information Server","vendor":"IBM","versions":[{"status":"affected","version":"11.7"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques."}],"value":"IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-319","description":"CWE-319 Cleartext Transmission of Sensitive Information","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-08-26T14:51:14.232Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7237604"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"InfoSphere Information Server, InfoSphere Information Server on Cloud  11.7.0.0 to 11.7.1.6  DT439751  --Apply InfoSphere Information Server version 11.7.1.0 <br>--Apply InfoSphere Information Server version 11.7.1.6<br><br>--Apply InfoSphere DataStage Flow Designer security patch<br>"}],"value":"InfoSphere Information Server, InfoSphere Information Server on Cloud  11.7.0.0 to 11.7.1.6  DT439751  --Apply InfoSphere Information Server version 11.7.1.0 \n--Apply InfoSphere Information Server version 11.7.1.6\n\n--Apply InfoSphere DataStage Flow Designer security patch"}],"source":{"discovery":"UNKNOWN"},"title":"IBM InfoSphere DataStage Flow Designer information disclosure","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-06-26T15:23:29.279197Z","id":"CVE-2025-36034","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-26T15:23:43.304Z"}}]}}