VulnerabilityModified
CVE-2016-8977
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests.
MEDIUM 5.3EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/license metric tool · ibm/bigfix inventory
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg21995014Vendor Advisory
- http://www.securityfocus.com/bid/95308Third Party Advisory, VDB Entry
- http://www.ibm.com/support/docview.wss?uid=swg21995014Vendor Advisory
- http://www.securityfocus.com/bid/95308Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.