Vulnerabilities > IBM > Bigfix Security Compliance Analytics

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-1201 Insufficiently Protected Credentials vulnerability in IBM Bigfix Security Compliance Analytics 1.9.79
IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
7.8
2017-06-15 CVE-2017-1197 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Bigfix Security Compliance Analytics 1.9.70
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
critical
9.8
2017-06-08 CVE-2017-1179 Inadequate Encryption Strength vulnerability in IBM Bigfix Security Compliance Analytics 1.9.70
IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
high complexity
ibm CWE-326
5.9
2017-06-07 CVE-2017-1196 Weak Password Requirements vulnerability in IBM Bigfix Security Compliance Analytics 1.9.70
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2017-06-07 CVE-2017-1178 Cross-site Scripting vulnerability in IBM Bigfix Security Compliance Analytics 1.9.70
IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1