IBM Sterling Control Center directory traversal
CVE-2023-35020
5.4MEDIUM
Summary
IBM Sterling Control Center version 6.3.0 is susceptible to a directory traversal vulnerability, which enables remote attackers to manipulate URL requests by including 'dot dot' sequences. This exploitation could lead to unauthorized access to sensitive files within the system. Attackers sending specially crafted URL requests may gain visibility into arbitrary files, highlighting a significant security risk. Proper mitigation measures should be implemented to secure the affected systems against potential attacks. For further information, visit IBM's advisory page linked below.
Affected Version(s)
Sterling Control Center 6.3.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved