PT-2018-4862 · Ibm · Healthcenter

Published

2018-06-04

·

Updated

2019-10-09

·

CVE-2016-10684

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions healthcenter versions (affected versions not specified)
Description The healthcenter agent downloads binary resources over HTTP, making it susceptible to man-in-the-middle (MITM) attacks. This could potentially lead to remote code execution (RCE) if an attacker intercepts the request and swaps the resources with a malicious version. The vulnerability can be exploited if the attacker has a privileged network position, allowing them to intercept and modify the response, resulting in code execution on the system running healthcenter.
Recommendations To mitigate this vulnerability, uninstall the healthcenter package and install the appmetrics package via the following commands: npm uninstall healthcenter -s npm install appmetrics -s

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10684
GHSA-J336-34Q7-CGJ3

Affected Products

Healthcenter