|
265711
|
3.7 |
LOW
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the …
|
CWE-310
Cryptographic Issues
|
CVE-2016-2951
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265712
|
6.5 |
MEDIUM
Network
|
ibm
|
bigfix_remote_control
|
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-2950
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265713
|
3.3 |
LOW
Local
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
|
CWE-200
Information Exposure
|
CVE-2016-2949
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265714
|
7.8 |
HIGH
Local
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-2948
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265715
|
9.8 |
CRITICAL
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
|
CWE-287
Improper Authentication
|
CVE-2016-2944
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265716
|
1.9 |
LOW
Local
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2016-2943
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265717
|
5.3 |
MEDIUM
Network
|
ibm
|
bigfix_remote_control
|
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.
|
CWE-200
Information Exposure
|
CVE-2016-2940
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265718
|
6.5 |
MEDIUM
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerabil…
|
CWE-200 CWE-20
Information Exposure Improper Input Validation
|
CVE-2016-2937
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265719
|
7.3 |
HIGH
Network
|
ibm
|
bigfix_remote_control
|
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
|
CWE-255
Credentials Management
|
CVE-2016-2936
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265720
|
5.3 |
MEDIUM
Network
|
ibm
|
bigfix_remote_control
|
The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.
|
CWE-20
Improper Input Validation
|
CVE-2016-2935
|
2024-11-21 11:49 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|