Known vulnerabilities in IBM Sterling Control Center

Software CPE: cpe:2.3:a:ibm_corporation:ibm_sterling_control_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 156
Public exploits: 12
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Sterling Control Center IBM Sterling Control Center is affected by 156 known vulnerabilities: 2 critical, 16 high, 93 medium, 45 low Critical High Medium Low

Vulnerabilities (156)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132273 - Incorrect Calculation
CVE-2025-14813
CWE-682 Medium
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 25.05.2026 SB2026052529
SB2026052540
SB2026052541
and 14 more
#VU132259 - Covert Timing Channel
CVE-2026-5598
CWE-385 Medium
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 25.05.2026 SB2026052530
SB2026052544
SB2026052931
and 12 more
#VU128373 - Protection Mechanism Failure
CVE-2026-22732
CWE-693 High
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 28.04.2026 SB20260427181
SB2026043058
SB2026050514
and 5 more
#VU128313 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-41044
CWE-94 Medium
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 28.04.2026 SB2026042852
SB2026050348
SB2026050349
and 5 more
#VU128312 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-40466
CWE-94 Medium
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 28.04.2026 SB2026042852
SB2026050348
SB2026050349
and 3 more
#VU128235 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-40977
CWE-59 Low
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 27.04.2026 SB20260427182
SB2026052513
SB2026052929
and 2 more
#VU128234 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-40975
CWE-338 Medium
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 27.04.2026 SB20260427182
SB2026052513
SB2026052929
and 3 more
#VU128233 - Improper Validation of Certificate with Host Mismatch
CVE-2026-40974
CWE-297 Medium
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 27.04.2026 SB20260427182
SB2026052513
SB20260528266
and 2 more
#VU128232 - Improper Access Control
CVE-2026-40973
CWE-284 Low
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 27.04.2026 SB20260427182
SB2026052513
SB2026052929
and 2 more
#VU125866 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-2332
CWE-444 Medium
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 14.04.2026 SB2026041433
SB2026050517
SB20260507308
and 9 more
#VU125816 - Sensitive Information in Resource Not Removed Before Reuse
CVE-2026-5795
CWE-226 High
No
No
6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4 11.04.2026 SB2026041112
SB20260507308
SB2026052932
and 3 more
#VU125791 - Improper Check or Handling of Exceptional Conditions
CVE-2026-39304
CWE-703 Medium
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 10.04.2026 SB2026041072
SB2026050348
SB2026050349
and 6 more
#VU125790 - Integer overflow
CVE-2026-40046
CWE-190 Medium
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 10.04.2026 SB2026041072
SB2026050348
SB2026050349
and 4 more
#VU125787 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-34197
CWE-94 Medium
Available
Exploited
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 10.04.2026 SB2026041071
SB2026050348
SB2026050349
and 8 more
#VU123577 - Missing release of memory after effective lifetime
CVE-2026-1605
CWE-401 Medium
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 05.03.2026 SB2026030559
SB2026050522
SB2026061616
and 2 more
#VU123576 - Improper input validation
CVE-2025-11143
CWE-20 Low
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 05.03.2026 SB2026030558
SB2026040716
SB2026042070
and 10 more
#VU123488 - Integer overflow
CVE-2025-66168
CWE-190 Medium
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 04.03.2026 SB2026030411
SB2026031501
SB2026031502
and 9 more
#VU121727 - Improper input validation
CVE-2026-21945
CWE-20 Medium
No
No
6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1 20.01.2026 SB20260120152
SB20260120153
SB20260120154
and 96 more
#VU121728 - Improper input validation
CVE-2026-21932
CWE-20 Medium
No
No
6.3.1.0.7, 6.4.1.0.1, 6.4.2.0.1 20.01.2026 SB20260120152
SB20260120153
SB20260120154
and 77 more
#VU116762 - Deserialization of Untrusted Data
CVE-2025-10492
CWE-502 Low
No
No
6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3 08.10.2025 SB2025100869
SB2026050515


Showing elements 1 - 20 out of 156