PT-2017-9902 · Ibm · Ibm Bigfix Inventory
Published
2017-02-01
·
Updated
2017-02-13
·
CVE-2016-8963
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM BigFix Inventory version 9
Description
The issue concerns the storage of potentially sensitive information in log files by IBM BigFix Inventory. This information could be accessed by a local user, potentially leading to unauthorized disclosure of sensitive data.
Recommendations
For IBM BigFix Inventory version 9, consider restricting access to log files to minimize the risk of sensitive information disclosure until a fix is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Bigfix Inventory