CVE-2016-0292: Infoleak
Published Aug 30, 2016
·Updated
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by reading a report.
Affected Software
4 affected components
IBM BigFix=9.0
IBM BigFix=9.1
IBM BigFix=9.2
IBM BigFix=9.5
Event History
Aug 30, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0292?
CVE-2016-0292 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0292?
To fix CVE-2016-0292, upgrade to IBM BigFix Platform version 9.5.2 or later.
3
What type of vulnerability is CVE-2016-0292?
CVE-2016-0292 is a local privilege escalation vulnerability that exposes cleartext passwords.
4
Who is impacted by CVE-2016-0292?
CVE-2016-0292 impacts local users of IBM BigFix Platform versions 9.0 through 9.5.1.
5
What can attackers do with CVE-2016-0292?
Attackers can exploit CVE-2016-0292 to discover cleartext system passwords from reports.