CVE-2016-0291: OS Command Injection
Published Feb 28, 2018
·Updated
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
Affected Software
3 affected components
IBM BigFix Platform>=9.1<9.1.8
IBM BigFix Platform>=9.2<9.2.8
IBM BigFix Platform=9.0
Event History
Feb 28, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0291?
CVE-2016-0291 has a medium severity rating due to its potential for allowing remote command execution by authenticated users.
2
How do I fix CVE-2016-0291?
To fix CVE-2016-0291, upgrade IBM BigFix Platform to versions 9.1.8 or 9.2.8 or later.
3
What types of users are affected by CVE-2016-0291?
CVE-2016-0291 affects remote authenticated users who have access to the report server.
4
What platforms are vulnerable to CVE-2016-0291?
CVE-2016-0291 affects IBM BigFix Platform versions 9.0, 9.1 prior to 9.1.8, and 9.2 prior to 9.2.8.
5
What actions can be taken to mitigate CVE-2016-0291?
Mitigation for CVE-2016-0291 includes applying the latest patches from IBM for the BigFix Platform.