CVE-2026-1567
7.1IBM · InfoSphere Information Server
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 contains an XML External Entity (XXE) vulnerability that allows authenticated attackers to retrieve sensitive server information.
Executive summary
A critical XML External Entity vulnerability in IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 permits authenticated attackers to conduct unauthorized information disclosure.
Vulnerability
The flaw is an Improper Restriction of XML External Entity Reference (CWE-611) occurring within the application, which can be triggered by an authenticated attacker to access sensitive local files or internal network resources.
Business impact
Successful exploitation of this vulnerability leads to the unauthorized disclosure of sensitive data, which may include configuration files, credentials, or internal system information. Given the CVSS score of 7.1, this represents a significant risk to confidentiality. If attackers access sensitive business intelligence or database configurations, it could facilitate further compromise of the broader enterprise data environment.
Remediation
Immediate Action: Apply the vendor-provided security patches or upgrade to the recommended maintenance levels as detailed in IBM support documentation for APAR DT461311.
Proactive Monitoring: Monitor server access logs for anomalous XML parsing requests or attempts to access restricted system files.
Compensating Controls: Ensure that the application is not configured to process untrusted XML input and deploy Web Application Firewall rules to block XML payloads containing external entity definitions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing IBM InfoSphere Information Server must prioritize the application of the specified patches to address this XXE vulnerability. Given the sensitive nature of the data typically handled by InfoSphere, remediation should be treated as a high priority to prevent potential data exfiltration and maintain system integrity.