CVE-2024-35112: IBM Control Center cross-site scripting
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Other sources
IBM Sterling Control Center could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35112?
CVE-2024-35112 has a medium severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2024-35112?
To fix CVE-2024-35112, apply the latest patches provided by IBM for Control Center versions 6.2.1 and 6.3.1.
What versions of IBM Control Center are affected by CVE-2024-35112?
IBM Control Center versions 6.2.1 and 6.3.1 are affected by CVE-2024-35112.
Can CVE-2024-35112 be exploited remotely?
Yes, CVE-2024-35112 can be exploited remotely by attackers to obtain sensitive information.
What type of information could be exposed due to CVE-2024-35112?
CVE-2024-35112 could expose sensitive technical error messages that may assist attackers in further exploits.