CVE-2025-1350

Summary

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

Affected Software

VendorProductVersion RangeStatus
IBMController11.0.0 <= 11.0.1 FP7affected
IBMController11.1.0 <= 11.1.3 FP1affected

Weaknesses

  • CWE-209: CWE-209 Generation of Error Message Containing Sensitive Information

References