CVE-2016-8967: Medium severity IBM License Metric Tool vulnerability
Published Feb 1, 2017
·Updated
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
Affected Software
13 affected components
IBM License Metric Tool=9.2.0
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
IBM BigFix Inventory=9.2
All of the following
IBM License Metric Tool=9.2.0
Any of the following
HP HP-UX
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Event History
Feb 1, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8967?
CVE-2016-8967 is considered a critical vulnerability due to the storage of user credentials in plain text.
2
How do I fix CVE-2016-8967?
To fix CVE-2016-8967, update to the latest version of IBM BigFix Inventory or implement a workaround to encrypt stored user credentials.
3
Who is affected by CVE-2016-8967?
CVE-2016-8967 affects users of IBM BigFix Inventory version 9.2.0.
4
What type of vulnerability is CVE-2016-8967?
CVE-2016-8967 is a security vulnerability related to improper credential storage.
5
Can CVE-2016-8967 lead to further attacks?
Yes, CVE-2016-8967 can lead to unauthorized access as the credentials are stored in clear text.