Known vulnerabilities in IBM Sterling Control Center
Vendor:
IBM Corporation
Software:
IBM Sterling Control Center
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_sterling_control_center:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
156
Public exploits:
12
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
6.4.2.0.4
6.4.1.0.3
6.3.1.0.9
6.4.2.0.2
6.4.2.0.3
6.4.1.0.2
6.3.1.0.8
6.3.1.0.7
6.4.1.0
6.4.2.0
6.4.2.0.1
6.4.1.0.1
6.3.1.0.6
6.3.1.0.5
6.4.0.0.2
6.3.1.0
6.4.0.0
6.4.0.0.1
6.3.1.0.0
6.3.1.0.1
6.2.1.0.15
6.3.1.0.4
6.2.0.0.17
6.2.1.0.14
6.3.1.0.3
6.3.0.0.6
6.2.1.0.13
6.3.1.0.2
6.3.0.0.4
6.1.3.0.18
6.3.0.0.3
6.2.1.0.12
6.1.3.0.17
6.3.0.0.2
6.2.1.0.11
6.1.3.0.16
6.3.0.0.1
6.2.1.0.10
6.1.3.0.15
6.2.1.0.9
6.2.1.0.7
6.2.1.0.6
6.2.1.0.5
6.2.1.0.4
6.2.1.0.3
6.2.1.0.2
6.2.1.0.1
6.1.3.0.14
6.1.3.0.13
6.1.3.0.12
6.1.3.0.11
6.1.3.0.10
6.1.3.0.9
6.1.3.0.8
6.1.3.0.7
6.1.3.0.6
6.1.3.0.5
6.1.3.0.4
6.1.3.0.3
6.1.3.0.2
6.1.3.0.1
6.2.1.0.8
6.1.3.0
6.2.0.0
6.2.1.0
Vulnerabilities (156)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132273 - Incorrect Calculation CVE-2025-14813 |
CWE-682 | Medium | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 25.05.2026 |
SB2026052529 SB2026052540 SB2026052541 and 14 more |
||
| #VU132259 - Covert Timing Channel CVE-2026-5598 |
CWE-385 | Medium | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 25.05.2026 |
SB2026052530 SB2026052544 SB2026052931 and 12 more |
||
| #VU128373 - Protection Mechanism Failure CVE-2026-22732 |
CWE-693 | High | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 28.04.2026 |
SB20260427181 SB2026043058 SB2026050514 and 5 more |
||
| #VU128313 - Improper Control of Generation of Code ('Code Injection') CVE-2026-41044 |
CWE-94 | Medium | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 28.04.2026 |
SB2026042852 SB2026050348 SB2026050349 and 5 more |
||
| #VU128312 - Improper Control of Generation of Code ('Code Injection') CVE-2026-40466 |
CWE-94 | Medium | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 28.04.2026 |
SB2026042852 SB2026050348 SB2026050349 and 3 more |
||
| #VU128235 - Improper Link Resolution Before File Access ('Link Following') CVE-2026-40977 |
CWE-59 | Low | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 27.04.2026 |
SB20260427182 SB2026052513 SB2026052929 and 2 more |
||
| #VU128234 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CVE-2026-40975 |
CWE-338 | Medium | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 27.04.2026 |
SB20260427182 SB2026052513 SB2026052929 and 3 more |
||
| #VU128233 - Improper Validation of Certificate with Host Mismatch CVE-2026-40974 |
CWE-297 | Medium | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 27.04.2026 |
SB20260427182 SB2026052513 SB20260528266 and 2 more |
||
| #VU128232 - Improper Access Control CVE-2026-40973 |
CWE-284 | Low | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 27.04.2026 |
SB20260427182 SB2026052513 SB2026052929 and 2 more |
||
| #VU125866 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-2332 |
CWE-444 | Medium | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 14.04.2026 |
SB2026041433 SB2026050517 SB20260507308 and 9 more |
||
| #VU125816 - Sensitive Information in Resource Not Removed Before Reuse CVE-2026-5795 |
CWE-226 | High | 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 | 11.04.2026 |
SB2026041112 SB20260507308 SB2026052932 and 3 more |
||
| #VU125791 - Improper Check or Handling of Exceptional Conditions CVE-2026-39304 |
CWE-703 | Medium | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 10.04.2026 |
SB2026041072 SB2026050348 SB2026050349 and 6 more |
||
| #VU125790 - Integer overflow CVE-2026-40046 |
CWE-190 | Medium | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 10.04.2026 |
SB2026041072 SB2026050348 SB2026050349 and 4 more |
||
| #VU125787 - Improper Control of Generation of Code ('Code Injection') CVE-2026-34197 |
CWE-94 | Medium | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 10.04.2026 |
SB2026041071 SB2026050348 SB2026050349 and 8 more |
||
| #VU123577 - Missing release of memory after effective lifetime CVE-2026-1605 |
CWE-401 | Medium | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 05.03.2026 |
SB2026030559 SB2026050522 SB2026061616 and 2 more |
||
| #VU123576 - Improper input validation CVE-2025-11143 |
CWE-20 | Low | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 05.03.2026 |
SB2026030558 SB2026040716 SB2026042070 and 10 more |
||
| #VU123488 - Integer overflow CVE-2025-66168 |
CWE-190 | Medium | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 04.03.2026 |
SB2026030411 SB2026031501 SB2026031502 and 9 more |
||
| #VU121727 - Improper input validation CVE-2026-21945 |
CWE-20 | Medium | 6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 96 more |
||
| #VU121728 - Improper input validation CVE-2026-21932 |
CWE-20 | Medium | 6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 77 more |
||
| #VU116762 - Deserialization of Untrusted Data CVE-2025-10492 |
CWE-502 | Low | 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 | 08.10.2025 |
SB2025100869 SB2026050515 |
Showing elements 1 - 20 out of 156