Sensitive Information Disclosure in IBM BigFix Inventory
CVE-2016-8977

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

IBM BigFix Inventory v9 contains a vulnerability that may allow unauthorized users to expose sensitive information via HTTP GET requests. This weakness can be exploited by an attacker to gain insights or access that could facilitate subsequent attacks on the system. Organizations using this version should take immediate action to secure their implementations and monitor for unauthorized access.

Affected Version(s)

BigFix Inventory = unspecified

BigFix Inventory 9.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.