IBM / Bigfix Platform
44 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-4058 | IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to a… | MEDIUM | 6.5 | May 20, 2019 |
| CVE-2019-4011 | IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al… | MEDIUM | 5.4 | May 20, 2019 |
| CVE-2018-2005 | IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions. IB… | LOW | 3.3 | May 20, 2019 |
| CVE-2019-4013 | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code executio… | CRITICAL | 9.9 | Apr 10, 2019 |
| CVE-2019-4061 | IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associ… | MEDIUM | 5.3 | Feb 27, 2019 |
| CVE-2018-1485 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session… | MEDIUM | 4.3 | Dec 12, 2018 |
| CVE-2018-1484 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be a… | LOW | 3.7 | Dec 12, 2018 |
| CVE-2018-1481 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unaut… | MEDIUM | 5.3 | Dec 12, 2018 |
| CVE-2018-1480 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Sit… | MEDIUM | 5.3 | Dec 12, 2018 |
| CVE-2018-1478 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victi… | MEDIUM | 6.1 | Dec 12, 2018 |
| CVE-2018-1476 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to mount furt… | HIGH | 7.5 | Dec 12, 2018 |
| CVE-2018-1474 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied… | MEDIUM | 6.1 | Dec 12, 2018 |
| CVE-2017-1231 | IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910. | HIGH | 7.8 | Oct 12, 2018 |
| CVE-2018-1600 | IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized acto… | HIGH | 8.6 | Jun 4, 2018 |
| CVE-2018-1479 | IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmi… | HIGH | 8.8 | Apr 27, 2018 |
| CVE-2018-1475 | IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force I… | CRITICAL | 9.8 | Apr 27, 2018 |
| CVE-2018-1473 | IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus al… | MEDIUM | 6.1 | Apr 27, 2018 |
| CVE-2016-0295 | Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentica… | HIGH | 8.8 | Feb 28, 2018 |
| CVE-2016-0291 | IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server acce… | HIGH | 8.8 | Feb 28, 2018 |
| CVE-2017-1229 | IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HT… | MEDIUM | 5.9 | Nov 13, 2017 |
| CVE-2017-1221 | IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers t… | CRITICAL | 9.8 | Nov 13, 2017 |
| CVE-2017-1521 | IBM Tivoli Endpoint Manager (for Lifecycle/Power/Patch) Platform and Applications (IBM BigFix Platform 9.2 and 9.5) is vulnerable to cross-site scripting. This… | MEDIUM | 6.1 | Oct 26, 2017 |
| CVE-2017-1232 | IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) transmits sensitive or security-critical data in cleartext in a communication channel that can be… | MEDIUM | 5.9 | Oct 26, 2017 |
| CVE-2017-1230 | IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpredictable… | MEDIUM | 5.3 | Oct 26, 2017 |
| CVE-2017-1228 | IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly… | LOW | 3.7 | Oct 26, 2017 |
Showing 1 to 25 of 44 CVEs