Required CVE Record Information
Description
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.3 | MEDIUM | 3.0 | CVSS:3.0/A:N/AC:L/AV:N/C:L/I:N/PR:N/S:U/UI:N/E:U/RC:C/RL:O |
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- exchange.xforce.ibmcloud.com: ibm-bigfix-cve20194061-info-disc(156869) vdb-entryx_transferred
- securityfocus.com: 107189 vdb-entryx_transferred
- http://www.ibm.com/support/docview.wss?uid=ibm10870242 x_transferred
- http://www.rapid7.com/db/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum x_transferred