CVE-2025-36173 PUBLISHED

InfoSphere Data Architect (IDA) 9.2.1 Vulnerability Fixes.

Assigner: ibm
Reserved: 15.04.2025 Published: 10.03.2026 Updated: 10.03.2026

Affected Product(s)Version(s)InfoSphere Data Architect9.2.1

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor IBM
Product InfoSphere Data Architect
Versions
  • affected from 9.2.1 to 3.1.4 (incl.)

Solutions

Remediation/Fixes IBM strongly recommends addressing the vulnerability now by upgrading to release 9.2.1 Upgraded Version shall be download from : 1. Linux : : https://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FInformation+Management%2FInfosphere+Data+Architect&fixids=IIDAV1_9.2_Linux_MP_ML&source=SAR 2. Windows : https://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FInformation+Management%2FInfosphere+Data+Architect&fixids=IIDAV1_9.2_WIN_MP_ML&source=SAR

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE