Executive brief
IBM Controller is a business application used for financial consolidation and planning. A vulnerability allows remote attackers to extract sensitive technical information through detailed error messages displayed in the browser, which can then be leveraged to mount further attacks on the system.
Technical details
The vulnerability is an information disclosure flaw (CWE-209) in IBM Controller where verbose error messages containing sensitive technical details are returned to unauthenticated remote clients. The root cause is improper error handling that fails to sanitize or redact system information in browser-facing error responses. An attacker can trigger this condition without authentication or user interaction, allowing reconnaissance for subsequent attacks. IBM has resolved this issue in Controller version 11.2.0; affected users on 11.0.0–11.0.1 FP7 and 11.1.0–11.1.3 FP1 should upgrade immediately.
Affected products
- IBM Controller 11.0.0 through 11.0.1 FP7, 11.1.0 through 11.1.3 FP1
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Fix available in IBM Controller 11.2.0