CVE-2016-8963: Infoleak
Published Feb 1, 2017
·Updated
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
Affected Software
13 affected components
IBM License Metric Tool=9.2.0
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
IBM BigFix Inventory<=9.2
All of the following
IBM License Metric Tool=9.2.0
Any of the following
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Event History
Feb 1, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8963?
CVE-2016-8963 is considered a moderate severity vulnerability due to the potential exposure of sensitive information in log files.
2
How do I fix CVE-2016-8963?
To fix CVE-2016-8963, ensure that sensitive log files have restricted access permissions to prevent unauthorized local users from reading them.
3
Which software versions are affected by CVE-2016-8963?
CVE-2016-8963 affects HCL BigFix Inventory versions up to and including 9.2.
4
What kind of information is exposed in CVE-2016-8963?
CVE-2016-8963 potentially exposes sensitive information contained within log files.
5
Is CVE-2016-8963 present in IBM License Metric Tool?
CVE-2016-8963 is specifically related to HCL BigFix Inventory and does not affect IBM License Metric Tool.