Vulnerabilities > IBM > Bigfix Platform > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-04-10 CVE-2019-4013 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges.
network
low complexity
ibm CWE-434
critical
9.0
2018-02-28 CVE-2016-0291 OS Command Injection vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access.
network
low complexity
ibm CWE-78
critical
9.0
2017-02-01 CVE-2016-6082 Use After Free vulnerability in IBM Bigfix Platform
IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition.
network
low complexity
ibm CWE-416
critical
10.0