Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.809368
Kategorie:Web application abuses
Titel:IBM BigFix (Formerly Tivoli Endpoint Manager) Multiple Vulnerabilities Oct16
Zusammenfassung:This host is installed with IBM BigFix; (Formerly Tivoli Endpoint Manager) and is prone to multiple vulnerabilities.
Beschreibung:Summary:
This host is installed with IBM BigFix
(Formerly Tivoli Endpoint Manager) and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to

- Cleartext system password is used.

- Improper validation of incoming http traffic.

- Improper validation of user-supplied input.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to obtain sensitive information and let local users discover the
cleartext system password by reading a report and hijack the authentication of
arbitrary users, perform cross-site scripting attacks, web cache poisoning,
and other malicious activities.

Affected Software/OS:
IBM BigFix (Formerly Tivoli Endpoint
Manager) versions 9.x before 9.5.2.

Solution:
Upgrade to IBM BigFix (Formerly Tivoli
Endpoint Manager) version 9.5.2, or later. Please see the references for more information.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 92467
BugTraq ID: 92468
BugTraq ID: 92464
Common Vulnerability Exposure (CVE) ID: CVE-2016-0292
Common Vulnerability Exposure (CVE) ID: CVE-2016-0397
http://www.securityfocus.com/bid/92467
Common Vulnerability Exposure (CVE) ID: CVE-2016-0295
XForce ISS Database: ibm-mdm-cve20160295-csrf(111363)
https://exchange.xforce.ibmcloud.com/vulnerabilities/111363
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.