Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2022-44758

Disclosure Date: October 11, 2023 (last updated October 24, 2023)
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
Attacker Value
Unknown

CVE-2022-44757

Disclosure Date: October 11, 2023 (last updated October 24, 2023)
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
Attacker Value
Unknown

CVE-2023-23344

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
Attacker Value
Unknown

CVE-2022-44756

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. 
Attacker Value
Unknown

CVE-2022-42454

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure.  This requires privileged network access.
Attacker Value
Unknown

CVE-2021-27757

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cleartext, attackers could potentially read it and gain access to sensitive information."