IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
| Software | From | Fixed in |
|---|---|---|
| ibm / controller | 11.1.0 | 11.1.0.x |
| ibm / controller | 11.0.0 | 11.0.0.x |
| ibm / controller | 11.0.1 | 11.0.1.x |