Show filters
72 Total Results
Displaying 21-30 of 72
Sort by:
Attacker Value
Unknown

CVE-2021-27762

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
Attacker Value
Unknown

CVE-2021-27761

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
Attacker Value
Unknown

CVE-2021-27766

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Attacker Value
Unknown

CVE-2021-27767

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Attacker Value
Unknown

CVE-2021-27765

Disclosure Date: April 21, 2022 (last updated October 07, 2023)
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Attacker Value
Unknown

CVE-2020-14248

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Attacker Value
Unknown

CVE-2020-14254

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
Attacker Value
Unknown

CVE-2020-4095

Disclosure Date: July 16, 2020 (last updated February 21, 2025)
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
Attacker Value
Unknown

CVE-2019-4058

Disclosure Date: May 20, 2019 (last updated November 27, 2024)
IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570.
Attacker Value
Unknown

CVE-2019-4011

Disclosure Date: May 20, 2019 (last updated November 27, 2024)
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155885.