Page 4 of 62 results (0.007 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

12 Oct 2018 — IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910. IBM BigFix Platform 9.5 - 9.5.9 almacena las credenciales de usuario en formato de texto plano, por lo que podrían ser leídos por un usuario local. IBM X-Force ID: 123910. • https://exchange.xforce.ibmcloud.com/vulnerabilities/123910 • CWE-522: Insufficiently Protected Credentials •

CVSS: 8.6EPSS: 0%CPEs: 2EXPL: 0

04 Jun 2018 — IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745. IBM BigFix Platform 9.2 y 9.5 transmite datos sensibles o críticos para la seguridad en texto claro en un canal de comunicación que puede ser rastreado por actores no autorizados. IBM X-Force ID: 143745. • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-319: Cleartext Transmission of Sensitive Information •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

27 Apr 2018 — IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761. IBM BigFix Platform 9.2 y 9.5 es vulnerable a ataques de Cross-Site Request Forgery (CSRF). Esto podría permitir que un atacante ejecute acciones maliciosas y no autorizadas transmitidas desde un usuario en el que la web confía. IBM X-Force ID: 140761. • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

27 Apr 2018 — IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691. IBM BigFix Platform 9.2 y 9.5 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades prevista... • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

27 Apr 2018 — IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756. IBM BigFix Platform 9.2 y 9.5 emplea una configuración de bloqueo de cuenta inadecuada que podría permitir que un atacante remoto descifre credenciales de cuenta por fuerza bruta. IBM X-Force ID: 140756. • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

28 Feb 2018 — Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en IBM BigFix Platform 9.0, 9.1, 9.2 y versiones 9.5 anteriores a la 9.5.2 permite que atacantes remotos secuestren la autenticación de usuarios arbitrarios para peticiones que inserten secuencias XSS. IBM X-Force... • http://www-01.ibm.com/support/docview.wss?uid=swg21985830 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 9.0EPSS: 5%CPEs: 3EXPL: 0

28 Feb 2018 — IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302. IBM BigFix Platform 9.0, versiones 9.1 anteriores a la 9.1.8 y versiones 9.2 anteriores a la 9.2.8, permite que usuarios autenticados remotos ejecuten comandos arbitrarios aprovechando el acceso al servidor de informes. IBM X-Force ID: 111302. • http://www-01.ibm.com/support/docview.wss?uid=swg21985748 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

13 Nov 2017 — IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861. IBM Tivoli Endpoint Manager (IBM BigFix 9.2 y 9.5) no requiere que los usuarios tengan contraseñas fuertes por defecto, lo que facilita que los atacantes comprometan las cuentas de usuario. IBM X-Force ID: 123861. • http://www.ibm.com/support/docview.wss?uid=swg22010177 • CWE-521: Weak Password Requirements •

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 0

13 Nov 2017 — IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908. IBM Tivoli Endpoint Manager (IBM BigFix 9.2 y 9.5) podría permitir que un atacante remoto obtenga información sensible, provocado por la imposibilidad de habilitar correctamente HTTP Str... • http://www.ibm.com/support/docview.wss?uid=swg22005246 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

26 Oct 2017 — IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123860. IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 y 9.5) revela información sensible a usuarios sin autorización. Esta información puede emplearse para ejecutar más ataques en el sistema. • http://www.ibm.com/support/docview.wss?uid=swg22009673 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •