PatchSiren

PatchSiren cyber security CVE debrief

CVE-2015-7493 IBM CVE debrief

IBM InfoSphere Information Server was reported vulnerable to a local command execution issue during installation under special circumstances. The impact described by NVD is exposure of sensitive information, and the issue is scoped to affected IBM InfoSphere Information Server releases rather than a network-facing remote exploit. IBM’s advisory is listed by NVD as the vendor patch reference.

Vendor
IBM
Product
Infosphere Information Server
CVSS
MEDIUM 4.7
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-08
Original CVE updated
2026-05-13
Advisory published
2017-02-08
Advisory updated
2026-05-13

Who should care

IBM InfoSphere Information Server administrators, installers, and security teams responsible for systems running versions 8.5, 8.7, 9.1, 11.3, or 11.5 should care most, especially where local users may have access to installation workflows or related privileges.

Technical summary

NVD assigns CVSS 3.0 vector CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating a local attack path, high complexity, low privileges required, no user interaction, and confidentiality impact only. The primary weakness listed is CWE-200. The affected CPEs in the NVD record include IBM InfoSphere Information Server 8.5, 8.7, 9.1, 11.3, and 11.5. The issue is described as a circumstance in which a local user could execute commands during installation processes, potentially exposing sensitive information.

Defensive priority

Moderate. The issue is local and high-complexity, but it can still expose sensitive information on affected installations, so patching and installation-control hygiene are important.

Recommended defensive actions

  • Check whether any affected IBM InfoSphere Information Server versions are installed in your environment.
  • Review and apply IBM’s vendor patch or mitigation guidance referenced by the NVD record.
  • Restrict who can run or influence installation processes on affected systems.
  • Limit local access to trusted administrative users and review installation-related permissions and workflows.

Evidence notes

This debrief is based on the supplied NVD record for CVE-2015-7493, published 2017-02-08 and modified 2026-05-13. The NVD record lists affected IBM InfoSphere Information Server versions 8.5, 8.7, 9.1, 11.3, and 11.5, with CVSS 3.0 vector AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N and weakness CWE-200. NVD references IBM advisory swg21982034 and SecurityFocus BID 90529.

Sources and references

Verified primary and authoritative sources

  • CVE-2015-7493 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2015-7493

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2015-7493 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2015-7493

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.