
CVE-2017-1231
https://notcve.org/view.php?id=CVE-2017-1231
12 Oct 2018 — IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910. IBM BigFix Platform 9.5 - 9.5.9 almacena las credenciales de usuario en formato de texto plano, por lo que podrían ser leídos por un usuario local. IBM X-Force ID: 123910. • https://exchange.xforce.ibmcloud.com/vulnerabilities/123910 • CWE-522: Insufficiently Protected Credentials •

CVE-2018-1600
https://notcve.org/view.php?id=CVE-2018-1600
04 Jun 2018 — IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel that can be sniffed by unauthorized actors. IBM X-Force ID: 143745. IBM BigFix Platform 9.2 y 9.5 transmite datos sensibles o críticos para la seguridad en texto claro en un canal de comunicación que puede ser rastreado por actores no autorizados. IBM X-Force ID: 143745. • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2018-1479
https://notcve.org/view.php?id=CVE-2018-1479
27 Apr 2018 — IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761. IBM BigFix Platform 9.2 y 9.5 es vulnerable a ataques de Cross-Site Request Forgery (CSRF). Esto podría permitir que un atacante ejecute acciones maliciosas y no autorizadas transmitidas desde un usuario en el que la web confía. IBM X-Force ID: 140761. • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2018-1473
https://notcve.org/view.php?id=CVE-2018-1473
27 Apr 2018 — IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691. IBM BigFix Platform 9.2 y 9.5 es vulnerable a Cross-Site Scripting. Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades prevista... • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-1475
https://notcve.org/view.php?id=CVE-2018-1475
27 Apr 2018 — IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756. IBM BigFix Platform 9.2 y 9.5 emplea una configuración de bloqueo de cuenta inadecuada que podría permitir que un atacante remoto descifre credenciales de cuenta por fuerza bruta. IBM X-Force ID: 140756. • http://www.ibm.com/support/docview.wss?uid=swg22015754 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVE-2016-0295
https://notcve.org/view.php?id=CVE-2016-0295
28 Feb 2018 — Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en IBM BigFix Platform 9.0, 9.1, 9.2 y versiones 9.5 anteriores a la 9.5.2 permite que atacantes remotos secuestren la autenticación de usuarios arbitrarios para peticiones que inserten secuencias XSS. IBM X-Force... • http://www-01.ibm.com/support/docview.wss?uid=swg21985830 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-0291
https://notcve.org/view.php?id=CVE-2016-0291
28 Feb 2018 — IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302. IBM BigFix Platform 9.0, versiones 9.1 anteriores a la 9.1.8 y versiones 9.2 anteriores a la 9.2.8, permite que usuarios autenticados remotos ejecuten comandos arbitrarios aprovechando el acceso al servidor de informes. IBM X-Force ID: 111302. • http://www-01.ibm.com/support/docview.wss?uid=swg21985748 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2017-1221
https://notcve.org/view.php?id=CVE-2017-1221
13 Nov 2017 — IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861. IBM Tivoli Endpoint Manager (IBM BigFix 9.2 y 9.5) no requiere que los usuarios tengan contraseñas fuertes por defecto, lo que facilita que los atacantes comprometan las cuentas de usuario. IBM X-Force ID: 123861. • http://www.ibm.com/support/docview.wss?uid=swg22010177 • CWE-521: Weak Password Requirements •

CVE-2017-1229
https://notcve.org/view.php?id=CVE-2017-1229
13 Nov 2017 — IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123908. IBM Tivoli Endpoint Manager (IBM BigFix 9.2 y 9.5) podría permitir que un atacante remoto obtenga información sensible, provocado por la imposibilidad de habilitar correctamente HTTP Str... • http://www.ibm.com/support/docview.wss?uid=swg22005246 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-1220
https://notcve.org/view.php?id=CVE-2017-1220
26 Oct 2017 — IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123860. IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 y 9.5) revela información sensible a usuarios sin autorización. Esta información puede emplearse para ejecutar más ataques en el sistema. • http://www.ibm.com/support/docview.wss?uid=swg22009673 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •