Impact
IBM Controller versions 11.0.0 through 11.0.1 FP7 and 11.1.0 through 11.1.3 FP1 contain a flaw that allows an authenticated user to bypass client‑side input validation of the file size field, enabling the upload of files larger than intended limits. Such oversized uploads can lead to resource exhaustion or allow the delivery of payloads that would normally be rejected, potentially compromising application functionality or exposing sensitive data.
Affected Systems
The affected systems are IBM Controller installations running any of the following releases: 11.0.0, 11.0.1 (fixed in FP7), 11.1.0, 11.1.3 (fixed in FP1). Users on the 11.0 or 11.1 release streams are advised to upgrade to the 11.2 stream, which includes the necessary fixes and is available at no additional charge.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is < 1%. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user exploiting the client‑side interface; no elevated privileges are required beyond valid user credentials. The overall risk is therefore moderate and should be mitigated promptly by applying the available updates.
OpenCVE Enrichment