VYPR

Bigfix Platform

by IBM

CVEs (46)

  • CVE-2018-1481LowDec 12, 2018
    risk 0.24cvss 3.7epss 0.01

    IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.

  • CVE-2017-1228LowOct 26, 2017
    risk 0.24cvss 3.7epss 0.01

    IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable the secure cookie attribute. An attacker could exploit this vulnerability to obtain sensitive information using…

  • CVE-2016-0297LowFeb 1, 2017
    risk 0.24cvss 3.7epss 0.01

    IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.

  • CVE-2018-2005LowMay 20, 2019
    risk 0.21cvss 3.3epss 0.00

    IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions. IBM X-Force ID: 155007

  • CVE-2016-0296LowFeb 1, 2017
    risk 0.21cvss 3.3epss 0.00

    IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.

  • CVE-2018-1485LowDec 12, 2018
    risk 0.20cvss 3.1epss 0.01

    IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM…

Page 3 of 3