CVE-2019-4061 Information
Feb 14, 2021
cve
Description
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.ibm.com/support/docview.wss?uid=ibm10870242 http://www.rapid7.com/db/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum http://www.securityfocus.com/bid/107189 https://exchange.xforce.ibmcloud.com/vulnerabilities/156869
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: