Vulnerabilities > IBM > Bigfix Platform > 9.5.9

DATE CVE VULNERABILITY TITLE RISK
2018-12-12 CVE-2018-1476 Information Exposure vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.0
2018-12-12 CVE-2018-1474 Injection vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input.
network
ibm CWE-74
4.3
2018-10-12 CVE-2017-1231 Insufficiently Protected Credentials vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1