Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2024-42194
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.
0
Attacker Value
Unknown
CVE-2024-23540
Disclosure Date: April 03, 2024 (last updated April 04, 2024)
The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application files from the Inventory server. The BigFix Inventory server does not properly restrict the served static file.
0
Attacker Value
Unknown
CVE-2021-27758
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account.
0
Attacker Value
Unknown
CVE-2021-27759
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application.
0
Attacker Value
Unknown
CVE-2016-8964
Disclosure Date: July 13, 2017 (last updated November 26, 2024)
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
0
Attacker Value
Unknown
CVE-2016-8962
Disclosure Date: April 26, 2017 (last updated November 26, 2024)
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.
0
Attacker Value
Unknown
CVE-2016-8977
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
0
Attacker Value
Unknown
CVE-2016-8963
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
0
Attacker Value
Unknown
CVE-2016-8967
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
0
Attacker Value
Unknown
CVE-2016-8961
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
0