First published: Wed Feb 28 2018(Updated: )
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | >=9.1<9.1.8 | |
IBM BigFix Platform | >=9.2<9.2.8 | |
IBM BigFix Platform | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0291 has a medium severity rating due to its potential for allowing remote command execution by authenticated users.
To fix CVE-2016-0291, upgrade IBM BigFix Platform to versions 9.1.8 or 9.2.8 or later.
CVE-2016-0291 affects remote authenticated users who have access to the report server.
CVE-2016-0291 affects IBM BigFix Platform versions 9.0, 9.1 prior to 9.1.8, and 9.2 prior to 9.2.8.
Mitigation for CVE-2016-0291 includes applying the latest patches from IBM for the BigFix Platform.