CVE-2019-4061
Summary
| CVE | CVE-2019-4061 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-27 22:29:00 UTC |
| Updated | 2023-02-03 20:26:00 UTC |
| Description | IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Bigfix Platform | All | All | All | All |
| Application | Ibm | Bigfix Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| IBM BigFix Relay Server Sites and Package Enum | MISC | www.rapid7.com | Third Party Advisory |
| IBM notice: The page you requested cannot be displayed | CONFIRM | www.ibm.com | Vendor Advisory |
| IBM BigFix Platform CVE-2019-4061 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.