First published: Tue Aug 30 2016(Updated: )
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by reading a report.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | =9.0 | |
IBM BigFix Platform | =9.1 | |
IBM BigFix Platform | =9.2 | |
IBM BigFix Platform | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0292 is classified as a medium severity vulnerability.
To fix CVE-2016-0292, upgrade to IBM BigFix Platform version 9.5.2 or later.
CVE-2016-0292 is a local privilege escalation vulnerability that exposes cleartext passwords.
CVE-2016-0292 impacts local users of IBM BigFix Platform versions 9.0 through 9.5.1.
Attackers can exploit CVE-2016-0292 to discover cleartext system passwords from reports.