IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with.
History

Fri, 07 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 17:00:00 +0000

Type Values Removed Values Added
Description IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with.
Title IBM Control Center external service interaction
First Time appeared Ibm
Ibm control Center
Weaknesses CWE-435
CPEs cpe:2.3:a:ibm:control_center:6.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:control_center:6.3.1.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm control Center
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-03-07T17:04:56.592Z

Reserved: 2023-09-15T01:12:28.344Z

Link: CVE-2023-43052

cve-icon Vulnrichment

Updated: 2025-03-07T17:04:50.823Z

cve-icon NVD

Status : Received

Published: 2025-03-07T17:15:18.060

Modified: 2025-03-07T17:15:18.060

Link: CVE-2023-43052

cve-icon Redhat

No data.