CVE-2019-4061: Infoleak
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4061?
CVE-2019-4061 is considered a medium severity vulnerability that allows unauthorized information gathering.
How do I fix CVE-2019-4061?
To fix CVE-2019-4061, ensure that authenticated access is enabled in the IBM BigFix Platform.
What versions of IBM BigFix Platform are affected by CVE-2019-4061?
CVE-2019-4061 affects IBM BigFix Platform versions 9.2 up to 9.2.16 and 9.5 up to 9.5.11.
What impact does CVE-2019-4061 have on IBM BigFix users?
CVE-2019-4061 allows an attacker to remotely query the relay and access details about updates and fixlets without authentication.
Is there a workaround for CVE-2019-4061?
The primary workaround for CVE-2019-4061 is to implement appropriate access controls and authentication methods.