CVE-2016-0297

LOW

IBM Tivoli Endpoint Manager - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94188
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21993214

Scores

CVSS v3 3.7
EPSS 0.0018
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (8)
ibm/bigfix_platform 9.0
ibm/bigfix_platform 9.1
ibm/bigfix_platform 9.2
ibm/bigfix_platform 9.5
IBM Corporation/BigFix Platform 9.0
IBM Corporation/BigFix Platform 9.1
IBM Corporation/BigFix Platform 9.2
IBM Corporation/BigFix Platform 9.5
Published Feb 01, 2017
Tracked Since Feb 18, 2026