Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8966


IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.


Published

2017-02-01T20:59:03.067

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm license_metric_tool 9.2.0 Yes
Operating System hp hp-ux * No
Operating System ibm aix * No
Operating System linux linux_kernel * No
Operating System microsoft windows * No
Operating System oracle solaris * No
Application ibm bigfix_inventory 9.2 Yes

References