{"api_version":"1","generated_at":"2026-07-23T08:38:02+00:00","cve":"CVE-2019-4061","urls":{"html":"https://cve.report/CVE-2019-4061","api":"https://cve.report/api/cve/CVE-2019-4061.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4061","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4061"},"summary":{"title":"CVE-2019-4061","description":"IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-02-27 22:29:00","updated_at":"2023-02-03 20:26:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/156869","name":"ibm-bigfix-cve20194061-info-disc(156869)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.rapid7.com/db/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum","name":"http://www.rapid7.com/db/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum","refsource":"MISC","tags":["Third Party Advisory"],"title":"IBM BigFix Relay Server Sites and Package Enum","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ibm.com/support/docview.wss?uid=ibm10870242","name":"http://www.ibm.com/support/docview.wss?uid=ibm10870242","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/107189","name":"107189","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"IBM BigFix Platform CVE-2019-4061 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4061","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4061","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4061","vulnerable":"1","versionEndIncluding":"9.2.16","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"bigfix_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4061","vulnerable":"1","versionEndIncluding":"9.5.11","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"bigfix_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2019-02-18T00:00:00","ID":"CVE-2019-4061","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"BigFix Platform","version":{"version_data":[{"version_value":"9.2"},{"version_value":"9.5"}]}}]},"vendor_name":"IBM"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869."}]},"impact":{"cvssv3":{"BM":{"A":"N","AC":"L","AV":"N","C":"L","I":"N","PR":"N","S":"U","SCORE":"5.300","UI":"N"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Obtain Information"}]}]},"references":{"reference_data":[{"name":"ibm-bigfix-cve20194061-info-disc(156869)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/156869"},{"name":"107189","refsource":"BID","url":"http://www.securityfocus.com/bid/107189"},{"name":"http://www.ibm.com/support/docview.wss?uid=ibm10870242","refsource":"CONFIRM","url":"http://www.ibm.com/support/docview.wss?uid=ibm10870242"},{"refsource":"MISC","name":"http://www.rapid7.com/db/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum","url":"http://www.rapid7.com/db/modules/auxiliary/gather/ibm_bigfix_sites_packages_enum"}]}},"nvd":{"publishedDate":"2019-02-27 22:29:00","lastModifiedDate":"2023-02-03 20:26:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"9.2","versionEndIncluding":"9.2.16","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"9.5","versionEndIncluding":"9.5.11","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4061","Ordinal":"141672","Title":"CVE-2019-4061","CVE":"CVE-2019-4061","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4061","Ordinal":"1","NoteData":"IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4061","Ordinal":"2","NoteData":"2019-02-27","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4061","Ordinal":"3","NoteData":"2019-03-21","Type":"Other","Title":"Modified"}]}}}