IBM Control Center
cpe:2.3:a:ibm:control_center:*:*:*:*:*:*:*
- 6.2.1
- 6.3.1
A vulnerability allowing HTTP header injection has been identified in IBM Control Center versions 6.2.1 prior to 6.3.1. This issue arises from inadequate validation of input in the HOST headers, potentially enabling attackers to perform various actions such as cross-site scripting, cache poisoning, or session hijacking.
Exploitation of this vulnerability could lead to HTTP header injection, allowing for cross-site scripting, cache poisoning, or session hijacking.
Users can upgrade to IBM Sterling Control Center version 6.3.1.0 iFix04 or version 6.2.1.0 iFix15. Instructions for downloading these versions are available on Fix Central.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.