CVE-2016-0397

MEDIUM

IBM BigFix <9.5.2 - Info Disclosure

Title source: llm

Description

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.

Scores

CVSS v3 5.9
EPSS 0.0021
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (5)

ibm/bigfix_webreports
ibm/bigfix_webreports
ibm/bigfix_webreports
ibm/bigfix_webreports
n/a/n/a

Timeline

Published Aug 30, 2016
Tracked Since Feb 18, 2026