Impact
The vulnerability allows a remote attacker to obtain sensitive information when IBM Controller generates a detailed technical error message in the browser. This information disclosure can provide attackers leverage to launch additional attacks against the system. The weakness is recorded as CWE‑209, which describes improper handling of error messages that expose sensitive data.
Affected Systems
Affected versions include IBM Controller 11.0.0 through 11.0.1 with fix pack 7 and IBM Controller 11.1.0 through 11.1.3 with fix pack 1. Customers running the 11.0 or 11.1 release streams should upgrade to the 11.2 release stream, which incorporates the latest security fixes, at no additional charge.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity of information disclosure. The EPSS score of < 1% provides a very low estimate of exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Based on the description, it is inferred that a remote attacker can trigger a detailed error message through the web interface, potentially leaking stack traces or configuration data. While the vulnerability does not directly alter system state, the disclosed information could be used to facilitate further attacks, such as credential theft or privilege escalation, especially if authentication is bypassed or session hijacking occurs.
OpenCVE Enrichment