← Vulnerability feed

Vulnerability record · CVE-2018-1994 · published 10 April 2019

CVE-2018-1994: Ibm infosphere information server on cloud sql injection vulnerability

Ibm · Infosphere Information Server On Cloud

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.

9.8 CVSS 3.0 Critical EPSS 1.6% · top 25.9% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1994 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40689Ibm infosphere information server sql injection vulnerabilityIBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could all…EPSS 0.54%9.8CVE-2022-40752Ibm infosphere information server command injection vulnerabilityIBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: …EPSS 1.8%8.8CVE-2020-4305Ibm infosphere information server deserialization of untrusted data vulnerabilityIBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deseriali…EPSS 4.5%8.5CVE-2018-1701Ibm infosphere information server vulnerabilityIBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process…EPSS 1.2%8.3CVE-2019-4185Ibm infosphere information server vulnerabilityIBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID:…EPSS 0.59%8.1CVE-2016-6059Ibm infosphere datastage xml external entity (xxe) vulnerabilityIBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…EPSS 1.5%7.8CVE-2022-22454Ibm infosphere information server on cloud os command injection vulnerabilityIBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a speciall…EPSS 0.36%7.1CVE-2018-1845Ibm infosphere information server xml external entity (xxe) vulnerabilityIBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remo…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2018-1994), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.