HTTP Header Injection Vulnerability in IBM Control Center
CVE-2023-35894
6.1MEDIUM
What is CVE-2023-35894?
IBM Control Center versions 6.2.1 through 6.3.1 exhibit a security flaw due to improper validation of input within the HOST headers. This vulnerability can be exploited by attackers, enabling them to execute various malicious activities such as cross-site scripting (XSS), cache poisoning, and session hijacking. Proper safeguards and updates are essential to mitigate this risk effectively.
Affected Version(s)
Control Center 6.2.1 <= 6.3.1