Description
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35545 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7174794 |
|
History
Mon, 27 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 25 Jan 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Title | IBM Control Center cross-site scripting | |
| First Time appeared |
Ibm
Ibm control Center |
|
| Weaknesses | CWE-80 | |
| CPEs | cpe:2.3:a:ibm:control_center:6.2.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:control_center:6.3.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm control Center |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-27T17:30:11.832Z
Reserved: 2024-05-09T16:27:02.677Z
Link: CVE-2024-35112
Updated: 2025-01-27T17:30:07.224Z
Status : Received
Published: 2025-01-25T14:15:28.910
Modified: 2025-01-25T14:15:28.910
Link: CVE-2024-35112
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD