IBM
IBM Bigfix Inventory: vulnerabilidades y CVE
IBM Bigfix Inventory tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-8964 | Crítica (9.8) | 2.2% | — | 13 jul 2017 | IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853. |
| CVE-2016-8962 | Media (5.9) | 1.3% | — | 26 abr 2017 | IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851. |
| CVE-2016-8977 | Media (5.3) | 1.1% | — | 1 feb 2017 | IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system. |
| CVE-2016-8963 | Media (5.5) | 0.31% | — | 1 feb 2017 | IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. |
| CVE-2016-8967 | Media (5.5) | 0.31% | — | 1 feb 2017 | IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user. |
| CVE-2016-8981 | Media (5.5) | 0.32% | — | 1 feb 2017 | IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. |
| CVE-2016-8980 | Alta (8.1) | 1.5% | — | 1 feb 2017 | IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly… |
| CVE-2016-8966 | Media (5.9) | 1.2% | — | 1 feb 2017 | IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain… |
| CVE-2016-8961 | Media (6.1) | 0.85% | — | 1 feb 2017 | IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this… |
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142