CVE-2023-43052 Details
Description
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with.
A vulnerability in IBM Control Center versions 6.2.1 through 6.3.1 allows for external service interaction attacks. This issue arises from improper validation of user-supplied input, enabling remote attackers to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By crafting suitable payloads, attackers can manipulate the application server into targeting other systems it can interact with.
Users can upgrade to IBM Sterling Control Center version 6.3.1.0 iFix04 or 6.2.1.0 iFix15. Instructions for downloading these versions are available on Fix Central.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7185102 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-435 | Improper Interaction Between Multiple Correctly-Behaving Entities | CISA-ADP |
| CWE-435 | Improper Interaction Between Multiple Correctly-Behaving Entities | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm control center | 6.2.1.0 6.3.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2025 | Initial Analysis | [email protected] |
| Mar 7, 2025 | New CVE Received | [email protected] |
| Mar 7, 2025 | CVE Modified | CISA-ADP |