IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with.
| Software | From | Fixed in |
|---|---|---|
| ibm / control_center | 6.2.1.0 | 6.2.1.0.x |
| ibm / control_center | 6.3.1.0 | 6.3.1.0.x |