First published: Wed Feb 01 2017(Updated: )
IBM Tivoli Endpoint Manager - Mobile Device Management (MDM) could allow a remote attacker to obtain sensitive information due to a missing HTTP Strict-Transport-Security Header through man in the middle techniques.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BigFix Platform | =9.0 | |
IBM BigFix Platform | =9.1 | |
IBM BigFix Platform | =9.2 | |
IBM BigFix Platform | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0297 has a medium severity level due to its potential for information exposure.
To fix CVE-2016-0297, implement the HTTP Strict-Transport-Security header on your IBM Tivoli Endpoint Manager deployments.
CVE-2016-0297 exploits a vulnerability that allows remote attackers to obtain sensitive information through man-in-the-middle attacks.
CVE-2016-0297 affects IBM BigFix Platform versions 9.0, 9.1, 9.2, and 9.5.
CVE-2016-0297 is primarily a server-side vulnerability affecting the configuration of the IBM Tivoli Endpoint Manager.