Vulnerability Name: | CVE-2016-8966 (CCN-118855) | ||||||||||||
Assigned: | 2016-12-27 | ||||||||||||
Published: | 2016-12-27 | ||||||||||||
Updated: | 2017-02-13 | ||||||||||||
Summary: | IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | ||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-8966 Source: CCN Type: IBM Security Bulletin 1995023 (BigFix Inventory) Vulnerability due to a missing HTTP Strict Transport Security header affects IBM License Metric Tool v9.x and IBM BigFix Inventory v9.x (CVE-2016-8966) Source: CONFIRM Type: Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg21995023 Source: BID Type: Third Party Advisory, VDB Entry 95138 Source: CCN Type: BID-95138 IBM License Metric Tool and BigFix Inventory CVE-2016-8966 Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-bigfix-cve20168966-info-disc(118855) Source: CCN Type: IBM Security Bulletin 0881400 (License Metric Tool) Cross-site scripting vulnerabilities affects IBM License Metric Tool v9.x and IBM BigFix Inventory v9.x (CVE-2019-4368) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |