PT-2025-2426 · Ibm · Ibm Control Center

CVE-2024-35112

·

Published

2025-01-25

·

Updated

2025-01-25

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: IBM Control Center versions 6.2.1 through 6.3.1
Description: The issue is related to the failure to neutralize script-related HTML tags on a web page, which could allow a remote attacker to execute arbitrary code or gain access to confidential information. When a detailed technical error message is returned in the browser, it may provide sensitive information that could be used in further attacks against the system.
Recommendations: For IBM Control Center version 6.2.1, update to a version that includes the fix for this issue. For IBM Control Center version 6.3.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to detailed technical error messages to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01204
CVE-2024-35112

Affected Products

Ibm Control Center