CVE-2025-14974
Received Received - Intake
Insecure Direct Object Reference in IBM InfoSphere Info Server

Publication date: 2026-03-25

Last updated on: 2026-03-26

Assigner: IBM Corporation

Description
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable due to Insecure Direct Object Reference (IDOR).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-25
Last Modified
2026-03-26
Generated
2026-05-07
AI Q&A
2026-03-26
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ibm infosphere_information_server From 11.7.0.0 (inc) to 11.7.1.6 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-14974 is an Insecure Direct Object Reference (IDOR) vulnerability affecting IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6.

This vulnerability is classified under CWE-639: Authorization Bypass Through User-Controlled Key, meaning that an attacker with low privileges can access objects or data they should not be authorized to access by manipulating references to those objects.

The vulnerability has a CVSS v3.1 base score of 5.7, indicating a moderate severity with a high impact on confidentiality but no impact on integrity or availability.


How can this vulnerability impact me? :

This vulnerability allows an attacker with low privileges on an adjacent network to access sensitive information that they should not be authorized to see, leading to a high confidentiality impact.

There is no impact on data integrity or system availability, but unauthorized disclosure of sensitive data could lead to information leakage.

Because the attack requires low privileges and no user interaction, it could be exploited relatively easily in environments where the attacker has some network access.


What immediate steps should I take to mitigate this vulnerability?

To mitigate the CVE-2025-14974 vulnerability in IBM InfoSphere Information Server, you should apply the fixes provided via APAR DT458648.

Upgrade your IBM InfoSphere Information Server to one of the following versions: 11.7.1.0, 11.7.1.6, or apply the 11.7.1.6 Service Pack 2.

Note that no workarounds or alternative mitigations are provided, so applying the official fixes or upgrading is the recommended immediate action.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability is an Insecure Direct Object Reference (IDOR) with a high confidentiality impact, which could potentially expose sensitive data.

However, the provided information does not explicitly discuss how this vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart