Vulnerability Details CVE-2016-0291
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.052
EPSS Ranking 89.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2016-0291
-
cpe:2.3:a:ibm:bigfix_platform:9.0
-
cpe:2.3:a:ibm:bigfix_platform:9.1
-
cpe:2.3:a:ibm:bigfix_platform:9.1.2
-
cpe:2.3:a:ibm:bigfix_platform:9.1.3
-
cpe:2.3:a:ibm:bigfix_platform:9.1.4
-
cpe:2.3:a:ibm:bigfix_platform:9.1.5
-
cpe:2.3:a:ibm:bigfix_platform:9.1.6
-
cpe:2.3:a:ibm:bigfix_platform:9.1.7
-
cpe:2.3:a:ibm:bigfix_platform:9.2
-
cpe:2.3:a:ibm:bigfix_platform:9.2.0
-
cpe:2.3:a:ibm:bigfix_platform:9.2.1
-
cpe:2.3:a:ibm:bigfix_platform:9.2.2
-
cpe:2.3:a:ibm:bigfix_platform:9.2.3
-
cpe:2.3:a:ibm:bigfix_platform:9.2.4
-
cpe:2.3:a:ibm:bigfix_platform:9.2.5
-
cpe:2.3:a:ibm:bigfix_platform:9.2.6
-
cpe:2.3:a:ibm:bigfix_platform:9.2.7