PT-2016-5298 · Ibm · Ibm Bigfix Remote Control

Published

2016-11-30

·

Updated

2016-12-03

·

CVE-2016-2952

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM BigFix Remote Control versions prior to 9.1.3
Description The issue makes it easier for remote attackers to obtain sensitive information by leveraging the use of HTTP, as the HSTS protection mechanism is not enabled.
Recommendations For versions prior to 9.1.3, update to version 9.1.3 or later to enable the HSTS protection mechanism and mitigate the risk of sensitive information being obtained by remote attackers.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-2952

Affected Products

Ibm Bigfix Remote Control