IBM Controller Denial of Service Vulnerability

MEDIUM (6.5) No Patch (6 days)

Threat Intelligence

Low Risk
EPSS Score: 0.03% chance of exploitation (percentile: 9%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The IBM Controller is enterprise HR software used by some organizations for employee management. This vulnerability allows attackers to cause a denial of service (DoS) attack on the system by exploiting an issue in the native AES/CBC encryption implementation, resulting in a buffer overflow and subsequent crash.

Am I affected?

Affected versions: 11.0.1, 11.1.1 If you don't recognise this software, you're probably not affected.

Affected Products

IBM / IBM Controller

How to fix

To fix this vulnerability, upgrade to a patched version of IBM Controller 11.1.2. Immediate mitigations include reducing network access to the affected instance (firewall it from the public internet) and monitoring for suspicious activity related to the DoS attack.

References