CVE-2016-2944
critical
CVSS v3
9.8
CVSS v2
5.0
VIR risk
9.8
Description
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21991878
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV89790
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | bigfix_remote_control | {"endIncluding":"9.1.2"} | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89790
- http://www-01.ibm.com/support/docview.wss?uid=swg21991878
- http://www.securityfocus.com/bid/94623
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89790
- http://www-01.ibm.com/support/docview.wss?uid=swg21991878
- http://www.securityfocus.com/bid/94623
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.