CVE-2019-4061
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
27/02/2019
Last modified:
03/02/2023
Description
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:* | 9.2 (including) | 9.2.16 (including) |
| cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:* | 9.5 (including) | 9.5.11 (including) |
To consult the complete list of CPE names with products and versions, see this page



