CVE-2016-8964

Severity
9.8CRITICAL
EPSS
2.4%
top 14.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 13
Latest updateMay 14

Description

IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDibm/bigfix_inventory9.09.2.8
CVEListV5ibm/bigfix_inventory9.2
NVDibm/license_metric_tool9.09.2.8

🔴Vulnerability Details

6
GHSA
GHSA-84gr-jc26-g5mr: IBM BigFix Inventory v9 92022-05-14
CVEList
CVE-2016-8964: IBM BigFix Inventory v9 92017-07-13
OSV
linux-raspi2 vulnerabilities2016-12-20
OSV
linux-snapdragon vulnerabilities2016-12-20
OSV
linux vulnerabilities2016-12-20

💬Community

1
Bugzilla
CVE-2015-8964 kernel: tty: Prevent ldisc drivers from re-using stale tty fields2016-12-14
CVE-2016-8964 (CRITICAL CVSS 9.8) | IBM BigFix Inventory v9 9.2 uses an | cvebase.io