CVE-2023-35020
IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could
IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874.
MEDIUM · CVSS 5.4
EPSS 0.00049
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules7
YARA rules0