CVE-2024-35114: IBM Control Center information disclosure
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
Other sources
IBM Sterling Control Center could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35114?
CVE-2024-35114 has a medium severity rating due to its potential for username enumeration.
How do I fix CVE-2024-35114?
To fix CVE-2024-35114, apply the available patches for IBM Control Center versions 6.2.1 and 6.3.1.
What versions of IBM Control Center are affected by CVE-2024-35114?
IBM Control Center versions 6.2.1 and 6.3.1 are affected by CVE-2024-35114.
What type of attack can be executed due to CVE-2024-35114?
CVE-2024-35114 allows a remote attacker to enumerate usernames from the affected system.
Is there a workaround for CVE-2024-35114 if patches cannot be applied immediately?
Currently, there's no official workaround for CVE-2024-35114, so applying patches as soon as possible is recommended.