PT-2025-2426 · Ibm · Ibm Control Center
Published
2025-01-25
·
Updated
2025-01-25
·
CVE-2024-35112
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
IBM Control Center versions 6.2.1 through 6.3.1
Description:
The issue is related to the failure to neutralize script-related HTML tags on a web page, which could allow a remote attacker to execute arbitrary code or gain access to confidential information. When a detailed technical error message is returned in the browser, it may provide sensitive information that could be used in further attacks against the system.
Recommendations:
For IBM Control Center version 6.2.1, update to a version that includes the fix for this issue.
For IBM Control Center version 6.3.1, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to detailed technical error messages to minimize the risk of exploitation.
Fix
Generation of Error Message Containing Sensitive Information
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Control Center