---
id: CVE-2025-36245
title: >-
  IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an
  authenticated user to execute arbitrary commands with elevated privileges on
  the system due to improper validation of user supplied input.
summary: >-
  IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an
  authenticated user to execute arbitrary commands with elevated privileges on
  the system due to improper validation of user supplied input.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: ibm
product: infosphere_information_server
affected:
  - 'infosphere_information_server >= 11.7, <= 11.7.1.6'
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36245'
references:
  - url: 'https://www.ibm.com/support/pages/node/7246170'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00447
epssPercentile: 0.36869
ingestedAt: '2026-10-09T09:31:00.992Z'
---

## Overview

IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

## Affected

- `infosphere_information_server >= 11.7, <= 11.7.1.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
