Vulnerability Description
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Bigfix Remote Control | <= 9.1.2 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89786Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21991884Vendor Advisory
- http://www.securityfocus.com/bid/94645Third Party AdvisoryVDB Entry
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV89786Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21991884Vendor Advisory
- http://www.securityfocus.com/bid/94645Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-2936?
CVE-2016-2936 is a vulnerability with a CVSS score of 7.3 (HIGH). IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
How severe is CVE-2016-2936?
CVE-2016-2936 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2936?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Bigfix Remote Control.