VendorsIBMsterling_control_centerall versions
Vulnerabilities

IBM Sterling Control Center

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2013-2968
An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.
Published 2013-06-19 · Modified
6.3EPSS 0.009
CVE-2023-35894
IBM Control Center HOST header injection
Published 2025-03-07 · Analyzed
6.1EPSS 0.002
CVE-2023-35020
IBM Sterling Control Center directory traversal
Published 2024-01-19 · Modified
5.4EPSS 0.005
CVE-2023-42007
IBM Sterling Control Center cross-site scripting
Published 2025-04-10 · Analyzed
5.4EPSS 0.002
CVE-2016-0252
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.
Published 2016-07-08 · Modified
5.1EPSS 0.003
CVE-2023-43035
IBM Sterling Control Center information disclosure
Published 2025-04-10 · Analyzed
4.0EPSS 0.002
CVE-2014-0925
Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
Published 2014-05-30 · Modified
3.5EPSS 0.011
CVE-2013-2969
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.
Published 2013-06-19 · Modified
3.5EPSS 0.008