IBM Control Center User Enumeration Vulnerability

Vulnerability

A user enumeration vulnerability has been identified in IBM Control Center versions 6.2.1 and 6.3.1. This vulnerability allows remote attackers to enumerate usernames by exploiting an observable discrepancy in login attempt responses.

Impact

Exploitation of this vulnerability could lead to unauthorized username enumeration, allowing attackers to gather valid usernames for potential further attacks.

Remediation

Users can upgrade to IBM Control Center version 6.3.1.0 iFix02 or 6.2.1.0 iFix14. Instructions for downloading these versions are available on Fix Central.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.