CVE-2016-8966: Infoleak
Published Feb 1, 2017
·Updated
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Affected Software
13 affected components
IBM License Metric Tool=9.2.0
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
IBM BigFix Inventory=9.2
All of the following
IBM License Metric Tool=9.2.0
Any of the following
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8966?
CVE-2016-8966 has a medium severity level, as it can lead to sensitive information disclosure.
2
How do I fix CVE-2016-8966?
To fix CVE-2016-8966, ensure that HTTP Strict Transport Security is properly enabled in IBM BigFix Inventory.
3
Who is affected by CVE-2016-8966?
CVE-2016-8966 primarily affects IBM BigFix Inventory version 9.2.
4
Can CVE-2016-8966 be exploited by remote attackers?
Yes, CVE-2016-8966 can be exploited by remote attackers through man-in-the-middle techniques.
5
What type of vulnerability is CVE-2016-8966?
CVE-2016-8966 is a security vulnerability related to improper configuration of HTTP Strict Transport Security.