Vulnerability Details CVE-2019-4061
IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed to the associated sites due to not enabling authenticated access. IBM X-Force ID: 156869.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.599
EPSS Ranking 98.1%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2019-4061
-
cpe:2.3:a:ibm:bigfix_platform:9.2
-
cpe:2.3:a:ibm:bigfix_platform:9.2.0
-
cpe:2.3:a:ibm:bigfix_platform:9.2.1
-
cpe:2.3:a:ibm:bigfix_platform:9.2.10
-
cpe:2.3:a:ibm:bigfix_platform:9.2.11
-
cpe:2.3:a:ibm:bigfix_platform:9.2.12
-
cpe:2.3:a:ibm:bigfix_platform:9.2.13
-
cpe:2.3:a:ibm:bigfix_platform:9.2.14
-
cpe:2.3:a:ibm:bigfix_platform:9.2.15
-
cpe:2.3:a:ibm:bigfix_platform:9.2.16
-
cpe:2.3:a:ibm:bigfix_platform:9.2.2
-
cpe:2.3:a:ibm:bigfix_platform:9.2.3
-
cpe:2.3:a:ibm:bigfix_platform:9.2.4
-
cpe:2.3:a:ibm:bigfix_platform:9.2.5
-
cpe:2.3:a:ibm:bigfix_platform:9.2.6
-
cpe:2.3:a:ibm:bigfix_platform:9.2.7
-
cpe:2.3:a:ibm:bigfix_platform:9.2.8
-
cpe:2.3:a:ibm:bigfix_platform:9.2.9
-
cpe:2.3:a:ibm:bigfix_platform:9.5
-
cpe:2.3:a:ibm:bigfix_platform:9.5.0
-
cpe:2.3:a:ibm:bigfix_platform:9.5.1
-
cpe:2.3:a:ibm:bigfix_platform:9.5.10
-
cpe:2.3:a:ibm:bigfix_platform:9.5.11
-
cpe:2.3:a:ibm:bigfix_platform:9.5.2
-
cpe:2.3:a:ibm:bigfix_platform:9.5.3
-
cpe:2.3:a:ibm:bigfix_platform:9.5.4
-
cpe:2.3:a:ibm:bigfix_platform:9.5.5
-
cpe:2.3:a:ibm:bigfix_platform:9.5.6
-
cpe:2.3:a:ibm:bigfix_platform:9.5.7
-
cpe:2.3:a:ibm:bigfix_platform:9.5.8
-
cpe:2.3:a:ibm:bigfix_platform:9.5.9