Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8977


IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.


Published

2017-02-01T22:59:01.027

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm license_metric_tool 9.2.0 Yes
Operating System hp hp-ux * No
Operating System ibm aix * No
Operating System linux linux_kernel * No
Operating System microsoft windows * No
Operating System oracle solaris * No
Application ibm bigfix_inventory 9.2 Yes

References