Show filters
72 Total Results
Displaying 21-30 of 72
Sort by:
Attacker Value
Unknown
CVE-2021-27762
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses
0
Attacker Value
Unknown
CVE-2021-27761
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
0
Attacker Value
Unknown
CVE-2021-27766
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
0
Attacker Value
Unknown
CVE-2021-27767
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
0
Attacker Value
Unknown
CVE-2021-27765
Disclosure Date: April 21, 2022 (last updated October 07, 2023)
The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
0
Attacker Value
Unknown
CVE-2020-14248
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
0
Attacker Value
Unknown
CVE-2020-14254
Disclosure Date: December 16, 2020 (last updated February 22, 2025)
TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.
0
Attacker Value
Unknown
CVE-2020-4095
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."
0
Attacker Value
Unknown
CVE-2019-4058
Disclosure Date: May 20, 2019 (last updated November 27, 2024)
IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570.
0
Attacker Value
Unknown
CVE-2019-4011
Disclosure Date: May 20, 2019 (last updated November 27, 2024)
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155885.
0