CVE-2016-2933
medium
CVSS v3
6.8
CVSS v2
6.8
VIR risk
6.8
Description
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.
Predictions
Exploit likelihood
77%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21991892
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV89780
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | bigfix_remote_control | {"endIncluding":"9.1.2"} | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89780
- http://www-01.ibm.com/support/docview.wss?uid=swg21991892
- http://www.securityfocus.com/bid/94986
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89780
- http://www-01.ibm.com/support/docview.wss?uid=swg21991892
- http://www.securityfocus.com/bid/94986
CWEs
CWE-22
Verify integrity in audit chain (admin only). AS-IS.