CVE-2016-6084: Input Validation
Published Feb 1, 2017
·Updated
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.
Affected Software
2 affected components
IBM BigFix Platform=9.0
IBM BigFix Platform=9.1
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6084?
CVE-2016-6084 is classified as a moderate severity vulnerability that can cause the BES server to crash.
2
How do I fix CVE-2016-6084?
To fix CVE-2016-6084, upgrade the IBM BigFix Platform to a version that is not vulnerable, such as 9.2 or later.
3
Who is affected by CVE-2016-6084?
CVE-2016-6084 affects IBM BigFix Platform versions 9.0 and 9.1.
4
What impact does CVE-2016-6084 have on systems?
Exploitation of CVE-2016-6084 can lead to a denial of service by crashing the BES server.
5
Can CVE-2016-6084 be exploited remotely?
CVE-2016-6084 requires an attacker to be on the local network to exploit the vulnerability.