Command Injection Vulnerability in IBM BigFix Platform
CVE-2016-0291

8.8HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
28 February 2018

Summary

IBM BigFix Platform versions 9.0, 9.1 (prior to 9.1.8), and 9.2 (prior to 9.2.8) are susceptible to a command injection vulnerability. Threat actors with authenticated access to the report server can exploit this flaw to execute arbitrary commands on the server, potentially compromising the system's integrity and confidentiality. Ensuring that all affected versions are updated is crucial for safeguarding sensitive information and enhancing the overall security posture.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.