CVE-2016-8966
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Affected (2)
Products: Ibm: License Metric Tool, Bigfix Inventory
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.2.0 |
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | All versions |
Ibm Aix | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Oracle Solaris | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.2 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.