CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Jul 13, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853. |
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851. |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system. |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user. |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system. |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 8.1 HIGH· v3 7.5 HIGH· v2 IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive...Show more |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensi...Show more |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Feb 1, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera...Show more |