cbcvebase.

Ibm Bigfix Platform vulnerabilities

44 known vulnerabilities affecting ibm/bigfix_platform.

Total CVEs
44
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH11MEDIUM24LOW5

Vulnerabilities

Page 3 of 3
CVE-2018-1484P4LOWCVSS 3.7≥ 9.2.0, ≤ 9.2.14≥ 9.5, ≤ 9.5.9+4 more2018-12-12
CVE-2018-1484 [LOW] CWE-384 CVE-2018-1484: IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain th
nvd
CVE-2016-0297P4LOWCVSS 3.7v9.0v9.1+2 more2017-02-01
CVE-2016-0297 [LOW] CWE-200 CVE-2016-0297: IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.
nvd
CVE-2018-2005P4LOWCVSS 3.3≥ 9.2, ≤ 9.2.17≥ 9.5, ≤ 9.5.12+2 more2019-05-20
CVE-2018-2005 [LOW] CWE-200 CVE-2018-2005: IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that coul IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local attacker with elevated permissions. IBM X-Force ID: 155007
nvd
CVE-2016-0296P4LOWCVSS 3.3v9.0v9.1+2 more2017-02-01
CVE-2016-0296 [LOW] CWE-532 CVE-2016-0296: IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive informatio IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
nvd
Ibm Bigfix Platform vulnerabilities | cvebase