CVE-2016-0297: Infoleak
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0297?
CVE-2016-0297 has a medium severity level due to its potential for information exposure.
How do I fix CVE-2016-0297?
To fix CVE-2016-0297, implement the HTTP Strict-Transport-Security header on your IBM Tivoli Endpoint Manager deployments.
What does CVE-2016-0297 exploit?
CVE-2016-0297 exploits a vulnerability that allows remote attackers to obtain sensitive information through man-in-the-middle attacks.
Which versions of IBM BigFix Platform are affected by CVE-2016-0297?
CVE-2016-0297 affects IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5.
Is CVE-2016-0297 a client or server-side vulnerability?
CVE-2016-0297 is primarily a server-side vulnerability affecting the configuration of the IBM Tivoli Endpoint Manager.