Filtered by vendor Ibm Subscriptions
Filtered by product Bigfix Platform Subscriptions
Total 44 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-1473 1 Ibm 1 Bigfix Platform 2024-11-21 N/A
IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691.
CVE-2017-1231 1 Ibm 1 Bigfix Platform 2024-11-21 N/A
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.
CVE-2016-0295 1 Ibm 1 Bigfix Platform 2024-11-21 N/A
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.
CVE-2016-0291 1 Ibm 1 Bigfix Platform 2024-11-21 N/A
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.