CVE-2016-0296: Low severity IBM BigFix Platform vulnerability
Published Feb 1, 2017
·Updated
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) stores potentially sensitive information in log files that could be available to a local user.
Affected Software
4 affected components
IBM BigFix Platform=9.0
IBM BigFix Platform=9.1
IBM BigFix Platform=9.2
IBM BigFix Platform=9.5
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-0296?
CVE-2016-0296 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-0296?
To fix CVE-2016-0296, ensure that log files do not contain sensitive information or implement proper access controls.
3
What systems are affected by CVE-2016-0296?
CVE-2016-0296 affects IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5.
4
What type of information is at risk with CVE-2016-0296?
CVE-2016-0296 may expose potentially sensitive information stored in log files.
5
Can a local user exploit CVE-2016-0296?
Yes, a local user could access sensitive information from the log files due to CVE-2016-0296.